PT-2026-5231 · Jishenghua · Jsherp

·

CVE-2026-1546

·

Published

2026-01-28

·

Updated

2026-02-09

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions jishenghua jshERP versions up to 3.6
Description A security issue exists in jishenghua jshERP. The getBillItemByParam function within the com.jsh.erp.datasource.mappers.DepotItemMapperEx component, specifically in the file /jshERP-boot/depotItem/importItemExcel, is susceptible to SQL injection. Manipulation of the barCodes argument can trigger this issue, and remote exploitation is possible. The exploit has been publicly disclosed.
Recommendations Versions up to 3.6: Address the SQL injection issue in the getBillItemByParam function of the com.jsh.erp.datasource.mappers.DepotItemMapperEx component. As a temporary workaround, restrict or carefully sanitize input to the barCodes argument.

Exploit

Fix

Special Elements Injection

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-1546

Affected Products

Jsherp