CVE-2025-55371
MEDIUM EPSS 25.3%
Published Aug 21, 202510mo ago · Modified Jun 17, 20261w ago
5.3 CVSS 3.1
Published Aug 21, 2025 10mo ago
Last Modified Jun 17, 2026 1w ago
Description
Incorrect access control in the component /controller/PersonController.java of jshERP v3.5 allows unauthorized attackers to obtain all the information of the handler by executing the getAllList method.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality Low
Integrity None
Availability None
Threat Intelligence
EPSS Exploit Probability
25.3% percentile
Exploit & Patch Status
Public Exploit Known
No Patch Available
Weaknesses 1
CWE-284
Affected Products 1
| Vendor | Product | Version | Range |
|---|---|---|---|
| jishenghua | jsherp | 3.5 | any |
References 3
- jsherp.com http://jsherp.com
- github.com https://github.com/cina666/CVE/blob/main/jshERP/%E8%B6%8A%E6%9D%83%E8%87%B4%E4%BB%BB%E6%84%8F%E6%8E%A5%E7%AE%A1%E8%B4%A6%E5%8F%B7.md
- github.com https://github.com/jishenghua/jshERP
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.