PT-2025-43650 · Jsherp · Jsherp

CVE-2025-60801

·

Published

2025-10-24

·

Updated

2025-10-28

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions jshERP versions prior to commit fbda24da
Description The software contains an unauthenticated remote code execution (RCE) issue via the jsh erp function. This allows for the execution of arbitrary code without authentication.
Recommendations Update jshERP to a version later than commit fbda24da.

Exploit

Fix

RCE

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-60801

Affected Products

Jsherp