Access Control Flaw in jshERP Product by Jishenghua
CVE-2025-55371
5.3MEDIUM
What is CVE-2025-55371?
An access control vulnerability in jshERP v3.5 allows unauthorized attackers to exploit the /controller/PersonController.java component. By executing the getAllList method, attackers can gain unauthorized access to sensitive information held by the handler, potentially jeopardizing user data and system integrity. This flaw underscores the importance of implementing robust access control measures to prevent unauthorized data exposure.
