CVE-2025-55370: Jishenghua Jsherp
High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.
Incorrect access control in the component \controller\ResourceController.java of jshERP v3.5 allows unauthorized attackers to obtain all the corresponding ID data by modifying the ID value.
Affected products
- Jishenghua Jsherp: version 3.5 only
Published 2025-08-21. Last modified 2026-07-05.