Huaxiaerp

    Dashboard / Vendors

    Products: 2
    Vulnerabilities: 6
    Known Exploited: 0
    1
    Critical Level Threats
    0
    High Level Threats
    5
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2024-24000

    jshERP v3.3 is vulnerable to Arbitrary File Upload. The jshERP-boot/systemConfig/upload interface does not check the uploaded file type, and the biz parameter can be spliced into the upload path, resulting in arbitrary file uploads with controllable paths.

    Last Modified: Jun 12, 2025
    Published: Feb 06, 2024

    CVE-2024-0491

    Huaxia ERP UserController.java password recovery

    Last Modified: Nov 21, 2024
    Published: Jan 13, 2024

    CVE-2024-0490

    Huaxia ERP getAllList information disclosure

    Last Modified: Jun 03, 2025
    Published: Jan 13, 2024

    CVE-2023-48894

    Incorrect Access Control vulnerability in jshERP V3.3 allows attackers to obtain sensitive information via the doFilter function.

    Last Modified: Nov 21, 2024
    Published: Nov 30, 2023

    CVE-2022-3825

    Huaxia ERP User Management sql injection

    Last Modified: Apr 15, 2025
    Published: Nov 02, 2022
    Items Per Page
    Huaxiaerp Vulnerabilities & Security CVEs | CVE-DB