jshERP up to commit fbda24da was discovered to contain an unauthenticated remote code execution (RCE) vulnerability via the jsh_erp function.
References
| Link | Resource |
|---|---|
| https://fushuling.com/index.php/2025/08/17/%e7%bb%95%e8%bf%87%e8%a1%a5%e4%b8%81%ef%bc%8c%e5%86%8d%e6%ac%a1%e5%ae%9e%e7%8e%b0%e5%8d%8e%e5%a4%8ferp%e6%9c%aa%e6%8e%88%e6%9d%83rce%e5%b7%b2%e4%bf%ae%e5%a4%8d/ | Exploit Third Party Advisory |
| https://github.com/jishenghua/jshERP/issues/132 | Exploit Issue Tracking Vendor Advisory |
Configurations
History
05 Nov 2025, 21:06
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Jishenghua
Jishenghua jsherp |
|
| CPE | cpe:2.3:a:jishenghua:jsherp:*:*:*:*:*:*:*:* | |
| References | () https://fushuling.com/index.php/2025/08/17/%e7%bb%95%e8%bf%87%e8%a1%a5%e4%b8%81%ef%bc%8c%e5%86%8d%e6%ac%a1%e5%ae%9e%e7%8e%b0%e5%8d%8e%e5%a4%8ferp%e6%9c%aa%e6%8e%88%e6%9d%83rce%e5%b7%b2%e4%bf%ae%e5%a4%8d/ - Exploit, Third Party Advisory | |
| References | () https://github.com/jishenghua/jshERP/issues/132 - Exploit, Issue Tracking, Vendor Advisory |
Information
Published : 2025-10-24 16:26
Updated : 2025-11-05 21:06
NVD link : CVE-2025-60801
Mitre link : CVE-2025-60801
CVE.ORG link : CVE-2025-60801
JSON object : View
Products Affected
jishenghua
- jsherp
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
