Security Advisory

CVE-2025-55371

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-08-21 00:00:00
Last updated 2025-08-21 19:53:13
Assigner mitre
State PUBLISHED

Description

Incorrect access control in the component /controller/PersonController.java of jshERP v3.5 allows unauthorized attackers to obtain all the information of the handler by executing the getAllList method.