CVE-2024-24000

Publication date

2024-02-06 00:00:00

Family

mitre

State

PUBLISHED

Description

jshERP v3.3 is vulnerable to Arbitrary File Upload. The jshERP-boot/systemConfig/upload interface does not check the uploaded file type, and the biz parameter can be spliced into the upload path, resulting in arbitrary file uploads with controllable paths.