CVE-2025-60800: High severity jshERP jshERP vulnerability
Published Oct 28, 2025
·Updated
Incorrect access control in the /jshERP-boot/user/info interface of jshERP up to commit 90c411a allows attackers to access sensitive information via a crafted GET request.
Affected Software
2 affected components
jshERP jshERP<=90c411a
jishenghua jshERP<2025-08-07
Event History
Oct 28, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-60800?
The severity of CVE-2025-60800 has been classified as high due to the potential exposure of sensitive information.
2
How do I fix CVE-2025-60800?
To fix CVE-2025-60800, you should update jshERP to a version later than commit 90c411a to ensure proper access controls are implemented.
3
What type of vulnerability is CVE-2025-60800?
CVE-2025-60800 is an access control vulnerability that allows unauthorized access to sensitive information.
4
Which versions of jshERP are affected by CVE-2025-60800?
CVE-2025-60800 affects all versions of jshERP up to and including commit 90c411a.
5
What can attackers do with CVE-2025-60800?
Attackers can exploit CVE-2025-60800 to access sensitive user information through crafted GET requests.