RULE(RULE ID:338169)

Rule General Information
Release Date: 2024-06-25
Rule Name: JshERP Sensitive Information Leakage Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: JshERP is an Enterprise Resource Planning (ERP) system developed by Huaxia Jishi, a Chinese software company. ERP systems are integrated software solutions designed to manage and optimize various business processes within an organization, including finance, procurement, production, sales, human resources, and supply chain management. There is a sensitive information leakage vulnerability in JshERP. Malicious attackers can bypass permission restrictions through suffiuses such as.ico and access the getAllList interface to obtain system user information, including account and password.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.