PT-2026-96208 · Jsherp · Jsherp
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
jshERP versions prior to 3.7
Description
Authenticated users can modify tenant system configuration due to improper validation of user privileges in the
updateSystemConfig() function within the SystemConfigService. This allows attackers to rewrite or delete tenant-wide settings, including company identity, stock rules, approval behavior, and printing configuration, via the 'systemConfig' endpoint.Recommendations
Update jshERP to version 3.7 or later.
As a temporary mitigation, restrict access to the 'systemConfig' endpoint to only highly privileged administrators.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jsherp