Home

Description

jshERP up to commit fbda24da was discovered to contain an unauthenticated remote code execution (RCE) vulnerability via the jsh_erp function.

PUBLISHED Reserved 2025-09-26 | Published 2025-10-24 | Updated 2025-10-24 | Assigner mitre

References

github.com/jishenghua/jshERP/issues/132

fushuling.com/...再次实现华夏erp未授权rce已修复/

cve.org (CVE-2025-60801)

nvd.nist.gov (CVE-2025-60801)

Download JSON