Huaxiaerp develops enterprise resource planning software whose vulnerability profile centers on its core ERP and JSHERP products. The disclosures skew toward serious outcomes, with a meaningful share reaching critical severity, and recur through application-layer weakness classes including exposure of sensitive information, improper input neutralization, privilege assignment errors, and unrestricted file uploads that are typical of web-facing business software. Defenders deploying this vendor's products should prioritize patching releases; current severity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Huaxiaerp over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-24000CRITICAL jshERP v3.3 is vulnerable to Arbitrary File Upload. The jshERP-boot/systemConfig/upload interface does not check the uploaded file type, and the biz parameter can be spliced into t | Feb 6, 2024 | 9.8 | 27 | NO | NO |
CVE-2022-3826MEDIUM A vulnerability was found in Huaxia ERP. It has been classified as problematic. This affects an unknown part of the file /depotHead/list of the component Retail Management. The man | Nov 2, 2022 | 6.5 | 23 | NO | NO |
CVE-2022-3825MEDIUM A vulnerability was found in Huaxia ERP 2.3 and classified as critical. Affected by this issue is some unknown functionality of the component User Management. The manipulation of t | Nov 2, 2022 | 6.5 | 22 | NO | NO |
CVE-2024-0491HIGH A vulnerability classified as problematic has been found in Huaxia ERP up to 3.1. Affected is an unknown function of the file src/main/java/com/jsh/erp/controller/UserController.ja | Jan 13, 2024 | 7.5 | 21 | NO | NO |
CVE-2024-0490HIGH A vulnerability was found in Huaxia ERP up to 3.1. It has been rated as problematic. This issue affects some unknown processing of the file /user/getAllList. The manipulation leads | Jan 13, 2024 | 7.5 | 21 | NO | NO |
CVE-2023-48894MEDIUM Incorrect Access Control vulnerability in jshERP V3.3 allows attackers to obtain sensitive information via the doFilter function. | Nov 30, 2023 | 6.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Huaxiaerp.
Media articles that mention a CVE ID that affects a product developed by Huaxiaerp — matched by CVE ID, not by vendor name.