CVE-2025-7948: jshERP updatePwd password recovery
Published Jul 22, 2025
·Updated
A vulnerability classified as problematic was found in jshERP up to 3.5. Affected by this vulnerability is an unknown functionality of the file /jshERP-boot/user/updatePwd. The manipulation leads to weak password recovery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
2 affected components
jshERP jshERP<=3.5
jishenghua jshERP<=3.5
Event History
Jul 22, 2025
CVE Published
via MITRE·01:04 AM
Data Sourced
via MITRE·01:04 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 AM
DescriptionSeverityWeaknessAffected Software
Jun 20, 58473
Event
via NVD·11:43 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-7948?
CVE-2025-7948 is classified as a problematic vulnerability.
2
How do I fix CVE-2025-7948?
To fix CVE-2025-7948, update jshERP to version 3.5 or later.
3
What functionality is affected by CVE-2025-7948?
CVE-2025-7948 affects the password recovery functionality located at /jshERP-boot/user/updatePwd.
4
Can CVE-2025-7948 be exploited remotely?
Yes, CVE-2025-7948 can be exploited remotely.
5
What type of attack does CVE-2025-7948 involve?
CVE-2025-7948 involves weak password recovery manipulation.