Fastjson Deserialization Vulnerability in JSH_ERP from Jishenghua
CVE-2025-51744
9.8CRITICAL
What is CVE-2025-51744?
A vulnerability has been identified in JSH_ERP version 2.3.1, allowing for fastjson deserialization attacks via the /user/addUser endpoint. This flaw could enable unauthorized access and exploitation of the application, highlighting the importance of implementing security measures to safeguard against potential threats. Immediate action is advised for users to update and mitigate risks.
