CVE-2025-55371: Medium severity jshERP jshERP vulnerability
Published Aug 21, 2025
·Updated
Incorrect access control in the component /controller/PersonController.java of jshERP v3.5 allows unauthorized attackers to obtain all the information of the handler by executing the getAllList method.
Affected Software
2 affected components
jshERP jshERP
jishenghua jshERP=3.5
Event History
Aug 21, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-55371?
CVE-2025-55371 is classified with a high severity due to incorrect access control allowing unauthorized data exposure.
2
How do I fix CVE-2025-55371?
To fix CVE-2025-55371, implement proper access controls in the /controller/PersonController.java to restrict unauthorized access.
3
What components are affected by CVE-2025-55371?
CVE-2025-55371 affects the /controller/PersonController.java component in jshERP v3.5.
4
What types of data can be accessed through CVE-2025-55371?
Through CVE-2025-55371, unauthorized attackers can access all information handled by the getAllList method.
5
Who is the vendor associated with CVE-2025-55371?
The vendor associated with CVE-2025-55371 is jshERP.