Access Control Flaw in jshERP by Jishenghua
CVE-2025-55366
5.3MEDIUM
What is CVE-2025-55366?
A security issue in the UserController component of jshERP v3.5 allows unauthorized users to bypass access controls, enabling them to reset user account passwords. This flaw facilitates horizontal privilege escalation, permitting attackers to gain access to other users’ accounts without proper authorization.
