Junglewise Threat Intelligence

CVE-2025-55371: jishenghua jshERP improper access control in PersonController

CVE-2025-55371 · Severity: medium · CVSS 5.3 · Published 2025-08-21

Technologies: Jishenghua jshERP. Vendors: Jishenghua.

Executive brief

jshERP, an open-source Enterprise Resource Planning (ERP) system used by small and medium-sized businesses for financial and inventory management, contains a security flaw in its person management component. An unauthorized attacker can bypass security controls to access a list of all system handlers and their associated information. This could lead to the exposure of internal staff details and organizational structure, potentially facilitating further targeted attacks or account takeovers.

Technical details

An improper access control vulnerability exists in the `getAllList` method within `com/jsh/erp/controller/PersonController.java` of jshERP v3.5. The vulnerability can be exploited by sending a specially crafted HTTP request to the `/jshERP-boot/user/login/../../person/getAllList` endpoint. By utilizing path traversal sequences and removing the `X-Access-Token` header, an unauthenticated attacker can bypass authorization checks. Successful exploitation allows the attacker to retrieve a complete list of handlers and their associated data from the database.

Affected products

  • jishenghua jshERP 3.5

Timeline

  • 2025-08-21: advisory: Initial disclosure of CVE-2025-55371

References

Related threats