Executive brief
jshERP, an open-source Enterprise Resource Planning (ERP) system used by small and medium-sized businesses for financial and inventory management, contains a security flaw in its supplier management component. An unauthorized attacker can bypass security controls to change the status (such as enabling or disabling) of any supplier record in the system. This could disrupt business operations, interfere with procurement workflows, and compromise the integrity of vendor data across different accounts.
Technical details
An improper access control vulnerability exists in the batchSetStatus method within the SupplierController.java component of jshERP v3.5. The flaw allows an attacker to perform path traversal (using /../ sequences) to reach the supplier management endpoint without a valid X-Access-Token. By sending a specially crafted HTTP request to the /jshERP-boot/user/login/../../supplier/batchSetStatus path, an unauthenticated remote attacker can modify the 'status' field for any supplier ID. This results in a horizontal privilege escalation where an attacker can manipulate vendor data belonging to any tenant or account.
Affected products
- jishenghua jshERP 3.5
Timeline
- 2025-08-21: advisory
- 2025-08-21: disclosed