PT-2026-96205 · Jsherp · Jsherp
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
jshERP versions prior to 3.7
Description
The software fails to redact password hashes in the '/user/info' endpoint. This allows authenticated users to retrieve unsalted MD5 password digests for any user by supplying specific user IDs. These hashes can be used for offline cracking or direct authentication bypass.
Recommendations
Update jshERP to a version newer than 3.6.
As a temporary workaround, restrict access to the '/user/info' endpoint to minimize the risk of exploitation.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jsherp