CVE-2026-105621 | jishenghua jshERP up to 3.5 Financial Receipt Update AccountHeadService.java updateAccountHeadAndDetail improper authorization (Issue 167)
A vulnerability classified as problematic has been found in jishenghua jshERP up to 3.5. Affected is the function updateAccountHeadAndDetail of the file jshERP-boot/src/main/java/com/jsh/erp/service/AccountHeadService.java of the component Financial Receipt Update Handler. Performing a manipulation results in improper authorization.
This vulnerability was named CVE-2026-105621. The attack may be initiated remotely. In addition, an exploit is available.
The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More