jshERP updatePwd password recovery

CVE Details

Basic Information

Title jshERP updatePwd password recovery
Type cve
Published 2025-07-22T01:04:32.354Z
Modified 2025-07-22T01:04:32.354Z

Product Information

Vendor n/a
Product jshERP
Version 3.0

CVSS Information

Base Score 5.3 (MEDIUM)
Attack Vector CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P

AI Analysis

AI Description A vulnerability in jshERP’s password recovery system allows remote attackers to exploit weak security mechanisms, potentially leading to unauthorized access.
AI Severity Medium
AI Vendor jshERP Community
AI Product jshERP
AI Version 3.0, 3.1, 3.2, 3.3, 3.4, 3.5

Affected Products

  • n/a jshERP 3.0
  • n/a jshERP 3.1
  • n/a jshERP 3.2
  • n/a jshERP 3.3
  • n/a jshERP 3.4
  • n/a jshERP 3.5

Additional Information

CWE List CWE-640
Source VulDB

Description

A vulnerability classified as problematic was found in jshERP up to 3.5. Affected by this vulnerability is an unknown functionality of the file /jshERP-boot/user/updatePwd. The manipulation leads to weak password recovery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.