CVE-2026-1549: jishenghua jshERP PluginController uploadPluginConfigFile path traversal
A vulnerability was identified in jishenghua jshERP up to 3.6. Affected by this vulnerability is an unknown functionality of the file /jshERP-boot/plugin/uploadPluginConfigFile of the component PluginController. Such manipulation of the argument configFile leads to path traversal. The attack may be launched remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1549?
CVE-2026-1549 has been classified as a medium severity vulnerability due to its potential for path traversal attacks.
How do I fix CVE-2026-1549?
To fix CVE-2026-1549, update jishenghua jshERP to version 3.6 or later, where the vulnerability is patched.
What is affected by CVE-2026-1549?
CVE-2026-1549 affects versions of jishenghua jshERP up to and including 3.6, specifically the PluginController component.
Can CVE-2026-1549 allow unauthorized file access?
Yes, CVE-2026-1549 can allow unauthorized users to access sensitive files through path traversal techniques.
Is there a workaround for CVE-2026-1549?
Disabling the upload functionality in the PluginController can serve as a temporary workaround for CVE-2026-1549 until a patch is applied.