PT-2025-48081 · Jishenghua · Jsherp
Published
2025-11-25
·
Updated
2025-12-02
·
CVE-2025-51742
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
jishenghua JSH ERP version 2.3.1
Description
An issue exists in the software where the
/material/getMaterialEnableSerialNumberList API endpoint directly passes the search query parameter to the parseObject() function. This introduces a Fastjson deserialization flaw that could allow for Remote Code Execution (RCE) through the use of JDBC payloads.Recommendations
Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the
/material/getMaterialEnableSerialNumberList endpoint. Avoid using the search parameter in the affected API endpoint until the issue is resolved.Fix
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jsherp