CVE-2025-60800

Severity CVSS v4.0:
Pending analysis
Type:
CWE-284 Improper Access Control
Publication date:
28/10/2025
Last modified:
06/11/2025

Description

Incorrect access control in the /jshERP-boot/user/info interface of jshERP up to commit 90c411a allows attackers to access sensitive information via a crafted GET request.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:jishenghua:jsherp:*:*:*:*:*:*:*:* 2025-08-07 (excluding)


References to Advisories, Solutions, and Tools