PT-2025-29413 · Jsherp · Jsherp

Shenxiusecurity

·

Published

2025-07-14

·

Updated

2025-11-06

·

CVE-2025-7566

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: jshERP versions up to 3.5
Description: A critical issue exists in jshERP that allows for path traversal. The exportExcelByParam function within the /src/main/java/com/jsh/erp/controller/SystemConfigController.java file is affected. Manipulation of the Title argument enables the exploitation of this issue, and it can be initiated remotely. The exploit has been publicly disclosed. The vendor was notified but did not respond.
Recommendations: Versions prior to 3.5: Address the path traversal issue in the exportExcelByParam function by sanitizing the Title argument.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-7566

Affected Products

Jsherp