CVE-2026-8320: jishenghua jshERP updatePlatformConfigByKey Endpoint UserService.java getUserByWeixinCode server-side request forgery
A security vulnerability has been detected in jishenghua jshERP up to 3.6. This affects the function getUserByWeixinCode of the file jshERP-boot/src/main/java/com/jsh/erp/service/UserService.java of the component updatePlatformConfigByKey Endpoint. Such manipulation of the argument weixinUrl leads to server-side request forgery. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8320?
CVE-2026-8320 is considered a significant vulnerability as it allows unauthorized access through the updatePlatformConfigByKey endpoint.
How do I fix CVE-2026-8320?
To fix CVE-2026-8320, it is recommended to update jishenghua jshERP to version 3.6.1 or later, ensuring proper validation in the getUserByWeixinCode function.
Which software versions are affected by CVE-2026-8320?
CVE-2026-8320 affects jishenghua jshERP versions up to and including 3.6.
What is the nature of the vulnerability described in CVE-2026-8320?
CVE-2026-8320 involves improper manipulation of the weixinUrl argument in the getUserByWeixinCode function.
Are there any known exploits for CVE-2026-8320?
Yes, CVE-2026-8320 can be exploited to gain unauthorized access to user information by manipulating requests to the affected endpoint.