PT-2024-20226 · Jsherp · Jsherp

Published

2024-02-06

·

Updated

2024-02-13

·

CVE-2024-24000

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions jshERP version 3.3
Description The issue concerns an Arbitrary File Upload vulnerability. The jshERP-boot/systemConfig/upload interface does not check the uploaded file type, and the biz parameter can be spliced into the upload path, resulting in arbitrary file uploads with controllable paths.
Recommendations For jshERP version 3.3, consider disabling the jshERP-boot/systemConfig/upload interface until a patch is available to prevent arbitrary file uploads. Restrict access to the biz parameter to minimize the risk of exploitation. Avoid using the biz parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-24000

Affected Products

Jsherp