Vulnerabilities > Huaxiaerp

DATE CVE VULNERABILITY TITLE RISK
2024-02-06 CVE-2024-24000 Unrestricted Upload of File with Dangerous Type vulnerability in Huaxiaerp Jsherp 3.3
jshERP v3.3 is vulnerable to Arbitrary File Upload.
network
low complexity
huaxiaerp CWE-434
critical
9.8
2024-01-13 CVE-2024-0491 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Huaxiaerp Huaxia ERP
A vulnerability classified as problematic has been found in Huaxia ERP up to 3.1.
network
low complexity
huaxiaerp CWE-640
7.5
2024-01-13 CVE-2024-0490 Information Exposure vulnerability in Huaxiaerp Huaxia ERP
A vulnerability was found in Huaxia ERP up to 3.1.
network
low complexity
huaxiaerp CWE-200
7.5
2023-11-30 CVE-2023-48894 Unspecified vulnerability in Huaxiaerp Jsherp 3.3
Incorrect Access Control vulnerability in jshERP V3.3 allows attackers to obtain sensitive information via the doFilter function.
network
low complexity
huaxiaerp
6.5
2022-11-02 CVE-2022-3825 Improper Enforcement of Message or Data Structure vulnerability in Huaxiaerp Huaxia ERP 2.3
A vulnerability was found in Huaxia ERP 2.3 and classified as critical.
network
low complexity
huaxiaerp CWE-707
6.5
2022-11-02 CVE-2022-3826 Incorrect Privilege Assignment vulnerability in Huaxiaerp Huaxia ERP
A vulnerability was found in Huaxia ERP.
network
low complexity
huaxiaerp CWE-266
6.5