PT-2025-30364 · Jsherp · Jsherp

Zast.Ai

·

Published

2025-07-22

·

Updated

2025-08-11

·

CVE-2025-7947

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions jshERP versions prior to 3.6
Description A critical issue exists in jshERP. The vulnerability affects an unknown function within the /user/delete file of the Account Handler component. Manipulation of the ID argument results in improper authorization. Remote exploitation is possible. The exploit has been publicly disclosed and may be utilized.
Recommendations jshERP versions prior to 3.6: Update to version 3.6 or later to address the improper authorization issue. As a temporary workaround, restrict access to the /user/delete file to minimize the risk of exploitation.

Exploit

Fix

Improper Authorization

Incorrect Privilege Assignment

IDOR

Weakness Enumeration

Related Identifiers

CVE-2025-7947

Affected Products

Jsherp