Executive brief
jshERP is an open-source ERP system for small and medium enterprises that manages inventory, sales, purchases, and finances. This vulnerability allows authenticated users to manipulate user-role assignments and access controls without proper authorization, enabling privilege escalation, account lockout, or unauthorized access to sensitive business functions.
Technical details
A missing authorization check (CWE-862) in the userBusiness CRUD endpoints (/userBusiness/add, /userBusiness/update, /userBusiness/delete) allows any authenticated user to create, modify, or delete rows in the jsh_user_business authorization-relation table. An attacker with valid credentials can tamper with user-role mappings and role-function relationships, escalating privileges or revoking access from other accounts within the tenant.
Affected products
- jishenghua jshERP through 3.6
Timeline
- 2026-09-21: disclosed