PatchSiren

jishenghua CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW jishenghua CVE published 2026-06-08

CVE-2026-11469

A flaw has been found in jishenghua jshERP up to 3.6. Impacted is the function insertPlatformConfig of the file jshERP-boot/src/main/java/com/jsh/erp/service/PlatformConfigService.java of the component platformConfig Add Endpoint. Executing a manipulation of the argument platformValue can lead to server-side request forgery. The attack may be performed from remote. The exploit has been published and may b [truncated]

LOW jishenghua CVE published 2026-06-08

CVE-2026-11467

A path traversal vulnerability has been detected in jishenghua jshERP up to 3.6. The vulnerability affects the function addAccountHeadAndDetail of the file jshERP-boot/src/main/java/com/jsh/erp/service/AccountHeadService.java of the component addAccountHeadAndDetail Endpoint. This vulnerability allows remote attackers to manipulate the argument fileName, leading to path traversal. The exploit has been dis [truncated]