CVE-2025-51745: Critical severity jishenghua JSH_ERP vulnerability
Published Nov 25, 2025
·Updated
An issue was discovered in jishenghua JSHERP 2.3.1. The /role/addcan endpoint is vulnerable to fastjson deserialization attacks.
Affected Software
2 affected components
jishenghua JSH_ERP
jishenghua jshERP<=2.3.1
Event History
Nov 25, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-51745?
CVE-2025-51745 has been classified as a high severity vulnerability due to its potential impact on user data and system integrity.
2
How do I fix CVE-2025-51745?
To remediate CVE-2025-51745, you should update to the latest version of Jishenghua JSH_ERP that addresses this deserialization vulnerability.
3
What systems are affected by CVE-2025-51745?
CVE-2025-51745 affects Jishenghua JSH_ERP version 2.3.1 specifically.
4
What type of attack does CVE-2025-51745 involve?
CVE-2025-51745 involves fastjson deserialization attacks that can lead to unauthorized access and remote code execution.
5
Is there a workaround for CVE-2025-51745?
Currently, no specific workaround has been provided for CVE-2025-51745, making an update to a secured version the best option.