CVE-2025-55366: Medium severity jshERP jshERP vulnerability
Incorrect access control in the component \controller\UserController.java of jshERP v3.5 allows attackers to arbitrarily reset user account passwords and execute a horizontal privilege escalation attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-55366?
CVE-2025-55366 has a medium severity rating due to its potential to allow unauthorized password resets and privilege escalation.
How do I mitigate CVE-2025-55366?
To mitigate CVE-2025-55366, ensure proper access controls are implemented in the UserController.java component to restrict unauthorized actions.
What systems are affected by CVE-2025-55366?
CVE-2025-55366 affects jshERP version 3.5.
What kind of attacks can CVE-2025-55366 enable?
CVE-2025-55366 can enable attackers to perform arbitrary password resets and undertake horizontal privilege escalation attacks.
Is there a public patch for CVE-2025-55366?
As of now, there is no publicly available patch specified for CVE-2025-55366, but users are advised to implement necessary access controls.