Executive brief
jshERP is an open-source ERP system used by small and mid-size businesses for inventory, sales, purchasing, and financial management. An authenticated user can modify role-based button permissions for any role without proper authorization checks, potentially allowing them to grant themselves or others elevated access to sensitive features like financial or inventory controls.
Technical details
The POST /userBusiness/updateBtnStr endpoint is missing authorization validation (CWE-862), allowing any authenticated user to supply arbitrary roleId and btnStr parameters to overwrite button-permission configurations for any role. The vulnerability requires valid authentication credentials but no elevated privilege, and the attacker gains the ability to reconfigure UI/button access controls for any role in the tenant.
Affected products
- jshERP Project jshERP through 3.6
Timeline
- 2026-09-21: disclosed