CVE-2025-8840: jshERP Endpoint deleteBatch improper authorization
A vulnerability was determined in jshERP up to 3.5. Affected is an unknown function of the file /jshERP-boot/user/deleteBatch of the component Endpoint. The manipulation of the argument ids leads to improper authorization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Different than CVE-2025-7947.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8840?
CVE-2025-8840 is categorized as a high severity vulnerability due to improper authorization allowing remote attacks.
How do I fix CVE-2025-8840?
To fix CVE-2025-8840, update jshERP to a version later than 3.5 that addresses this vulnerability.
What component is affected by CVE-2025-8840?
CVE-2025-8840 affects the Endpoint component located in the jshERP-boot/user/deleteBatch function.
Can CVE-2025-8840 be exploited remotely?
Yes, CVE-2025-8840 can be exploited remotely due to improper authorization in the affected component.
What software versions are affected by CVE-2025-8840?
CVE-2025-8840 affects jshERP versions up to and including 3.5.