Vulnerabilities > Huaxiaerp > Jsherp

DATE CVE VULNERABILITY TITLE RISK
2024-02-06 CVE-2024-24000 Unrestricted Upload of File with Dangerous Type vulnerability in Huaxiaerp Jsherp 3.3
jshERP v3.3 is vulnerable to Arbitrary File Upload.
network
low complexity
huaxiaerp CWE-434
critical
9.8
2023-11-30 CVE-2023-48894 Unspecified vulnerability in Huaxiaerp Jsherp 3.3
Incorrect Access Control vulnerability in jshERP V3.3 allows attackers to obtain sensitive information via the doFilter function.
network
low complexity
huaxiaerp
6.5