CVE-2024-24000

CRITICAL

Huaxiaerp Jsherp - Unrestricted File Upload

Title source: rule
STIX 2.1

Description

jshERP v3.3 is vulnerable to Arbitrary File Upload. The jshERP-boot/systemConfig/upload interface does not check the uploaded file type, and the biz parameter can be spliced into the upload path, resulting in arbitrary file uploads with controllable paths.

Scores

CVSS v3 9.8
EPSS 0.0016
EPSS Percentile 36.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-434
Status published
Products (1)
huaxiaerp/jsherp 3.3
Published Feb 06, 2024
Tracked Since Feb 18, 2026