Executive brief
jshERP, an open-source Enterprise Resource Planning (ERP) system used for business management, contains a security flaw in its role management component. An unauthorized attacker can bypass security checks to view sensitive role information or modify supplier statuses across different business accounts. This could lead to unauthorized access to corporate data, disruption of supply chain operations, and potential reputational damage.
Technical details
An improper access control vulnerability exists in the `allList` method within `RoleController.java` of jshERP v3.5. The flaw stems from insufficient validation of authorization tokens when processing specific API requests. By utilizing path traversal sequences (e.g., `/jshERP-boot/user/login/../../role/allList`) and removing the `X-Access-Token` header, an unauthenticated attacker can bypass security filters. This allows the attacker to retrieve role information for all accounts or modify supplier statuses. The vulnerability is exploitable over the network without valid credentials, though some reports suggest it may require minimal user interaction or specific request formatting via tools like Burp Suite.
Affected products
- jishenghua jshERP 3.5
Timeline
- 2025-08-21: disclosed: Initial disclosure of CVE-2025-55368
- 2025-08-21: advisory: NVD publication date