Path Traversal Vulnerability in jshERP by Jishenghua
CVE-2025-7566
Key Information:
- Vendor
Jishenghua
- Status
- Vendor
- CVE Published:
- 14 July 2025
Badges
What is CVE-2025-7566?
A vulnerability exists in jshERP versions up to 3.5, specifically within the exportExcelByParam function found in the SystemConfigController.java file. This flaw allows attackers to manipulate the Title argument, potentially leading to unauthorized access and exposure of sensitive files on the server. Given that the attack can be executed remotely, it poses a significant risk to users. Despite early notifications to the vendor about the flaw, no response or remedy has been provided, making it imperative for users of affected versions to implement immediate security measures.
Affected Version(s)
jshERP 3.0
jshERP 3.1
jshERP 3.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved