Huaxiaerp
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Huaxiaerp product.
RSS Feeds for Huaxiaerp security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Huaxiaerp products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Huaxiaerp Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 0 vulnerabilities in Huaxiaerp. Huaxiaerp did not have any published security vulnerabilities last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 0 | 0.00 |
| 2025 | 0 | 0.00 |
| 2024 | 3 | 8.27 |
| 2023 | 1 | 6.50 |
| 2022 | 2 | 6.50 |
It may take a day or so for new Huaxiaerp vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Huaxiaerp Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2024-24000 | Feb 06, 2024 |
Arbitrary File Upload in jshERP v3.3 via Upload Path ManipulationjshERP v3.3 is vulnerable to Arbitrary File Upload. The jshERP-boot/systemConfig/upload interface does not check the uploaded file type, and the biz parameter can be spliced into the upload path, resulting in arbitrary file uploads with controllable paths. |
|
| CVE-2024-0491 | Jan 13, 2024 |
Huaxia ERP <3.2 weak password recovery in UserController.javaA vulnerability classified as problematic has been found in Huaxia ERP up to 3.1. Affected is an unknown function of the file src/main/java/com/jsh/erp/controller/UserController.java. The manipulation leads to weak password recovery. It is possible to launch the attack remotely. Upgrading to version 3.2 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-250596. |
|
| CVE-2024-0490 | Jan 13, 2024 |
Huaxia ERP <=3.1 Info Disclosure via /user/getAllList (Remote)A vulnerability was found in Huaxia ERP up to 3.1. It has been rated as problematic. This issue affects some unknown processing of the file /user/getAllList. The manipulation leads to information disclosure. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 3.2 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-250595. |
|
| CVE-2023-48894 | Nov 30, 2023 |
jshERP V3.3 DoFilter Access Control Bypass Allows Sensitive Data LeakIncorrect Access Control vulnerability in jshERP V3.3 allows attackers to obtain sensitive information via the doFilter function. |
|
| CVE-2022-3826 | Nov 02, 2022 |
Huaxia ERP RetailMgmt Info Disclosure via /depotHead/list SearchA vulnerability was found in Huaxia ERP. It has been classified as problematic. This affects an unknown part of the file /depotHead/list of the component Retail Management. The manipulation of the argument search leads to information disclosure. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-212793 was assigned to this vulnerability. |
|
| CVE-2022-3825 | Nov 02, 2022 |
Critical SQLi via User Management login in Huaxia ERP 2.3A vulnerability was found in Huaxia ERP 2.3 and classified as critical. Affected by this issue is some unknown functionality of the component User Management. The manipulation of the argument login leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-212792. |
|