CVE-2025-51742: Critical severity jishenghua JSH_ERP vulnerability
An issue was discovered in jishenghua JSHERP 2.3.1. The /material/getMaterialEnableSerialNumberList endpoint passes the search query parameter directly to parseObject(), introducing a Fastjson deserialization vulnerability that can lead to RCE via JDBC payloads.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-51742?
CVE-2025-51742 is considered a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2025-51742?
To fix CVE-2025-51742, update to the latest version of Jishenghua JSH_ERP that addresses the Fastjson deserialization vulnerability.
What are the risks associated with CVE-2025-51742?
The risks of CVE-2025-51742 include unauthorized remote code execution, which can compromise the entire system.
Which versions of Jishenghua JSH_ERP are affected by CVE-2025-51742?
CVE-2025-51742 affects Jishenghua JSH_ERP version 2.3.1.
Is CVE-2025-51742 exploitabl in a production environment?
Yes, CVE-2025-51742 can be exploited in a production environment if the vulnerable endpoint is exposed to untrusted input.