CyberRota Analysis
AI-GeneratedjshERP versions up to 3.6 are vulnerable due to inadequate user privilege validation in the SystemConfigService.updateSystemConfig function, enabling authenticated users to alter critical tenant-wide settings. This flaw allows attackers to manipulate configurations related to company identity, stock rules, approval processes, and printing settings, potentially leading to significant operational disruptions. Organizations utilizing jshERP should prioritize patching this vulnerability to safeguard their system configurations and maintain data integrity.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
jshERP through 3.6 fails to properly validate user privileges in SystemConfigService.updateSystemConfig, allowing authenticated users to modify tenant system configuration. Attackers can rewrite or delete tenant-wide settings covering company identity, stock rules, approval behavior, and printing configuration through the systemConfig endpoint.