PT-2025-43650 · Jsherp · Jsherp

Published

2025-10-24

·

Updated

2025-10-28

·

CVE-2025-60801

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions jshERP versions prior to commit fbda24da
Description The software contains an unauthenticated remote code execution (RCE) issue via the jsh erp function. This allows for the execution of arbitrary code without authentication.
Recommendations Update jshERP to a version later than commit fbda24da.

Exploit

Fix

RCE

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-60801

Affected Products

Jsherp