PT-2025-41265 · Unknown · Redragon-Erp
Changeyourway
+1
·
Published
2025-10-08
·
Updated
2025-10-08
·
CVE-2025-60830
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
redragon-erp version 1.0
Description
The software contains a Shiro deserialization issue stemming from the use of a default Shiro key. This could allow for unauthorized access or control of the system.
Recommendations
Replace the default Shiro key with a strong, randomly generated key.
Exploit
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Redragon-Erp