CVE-2025-60800: Jishenghua Jsherp

High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.

Incorrect access control in the /jshERP-boot/user/info interface of jshERP up to commit 90c411a allows attackers to access sensitive information via a crafted GET request.

Affected products

  • Jishenghua Jsherp: before 2025-08-07 (fixed in 2025-08-07)

Published 2025-10-28. Last modified 2026-06-17.