CVE-2026-1588: jishenghua jshERP installByPath install path traversal
A vulnerability was found in jishenghua jshERP up to 3.6. The impacted element is the function install of the file /jshERP-boot/plugin/installByPath of the component com.gitee.starblues.integration.operator.DefaultPluginOperator. The manipulation of the argument path results in path traversal. It is possible to launch the attack remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1588?
CVE-2026-1588 is classified as a medium-severity vulnerability due to its potential for path traversal exploitation.
How do I fix CVE-2026-1588?
To fix CVE-2026-1588, you should upgrade jishenghua jshERP to the latest version beyond 3.6 where the vulnerability has been addressed.
What components are affected by CVE-2026-1588?
CVE-2026-1588 affects the install functionality within the DefaultPluginOperator of jishenghua jshERP versions up to 3.6.
What type of vulnerability is CVE-2026-1588?
CVE-2026-1588 is a path traversal vulnerability that allows an attacker to manipulate file paths for unauthorized access.
Who is impacted by CVE-2026-1588?
Users of jishenghua jshERP up to version 3.6 are impacted by CVE-2026-1588 and should take action to mitigate the risk.