CVE-2026-94414 | jishenghua jshERP up to 3.6 updateBtnStr roleId/btnStr improper authorization
A vulnerability was found in jishenghua jshERP up to 3.6. It has been rated as problematic. The affected element is an unknown function of the file /userBusiness/updateBtnStr. This manipulation of the argument roleId/btnStr causes improper authorization.
This vulnerability is registered as CVE-2026-94414. Remote exploitation of the attack is possible. No exploit is available.VulDB Recent EntriesRead More