PT-2023-31002 · Jsherp · Jsherp

Aoaoaoeo

·

Publicado

2023-11-30

·

Atualizado

2023-12-06

·

CVE-2023-48894

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions jshERP version 3.3
Description The issue allows attackers to obtain sensitive information due to incorrect access control. This is achieved via the doFilter function.
Recommendations For jshERP version 3.3, consider restricting access to the doFilter function as a temporary workaround until a patch is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2023-48894

Produtos afetados

Jsherp