Metrics
Affected Vendors & Products
Thu, 29 Jan 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 29 Jan 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was found in jishenghua jshERP up to 3.6. The impacted element is the function install of the file /jshERP-boot/plugin/installByPath of the component com.gitee.starblues.integration.operator.DefaultPluginOperator. The manipulation of the argument path results in path traversal. It is possible to launch the attack remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet. | |
| Title | jishenghua jshERP installByPath install path traversal | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-01-29T14:29:46.680Z
Reserved: 2026-01-29T06:01:32.972Z
Link: CVE-2026-1588
Updated: 2026-01-29T14:29:42.547Z
Status : Received
Published: 2026-01-29T14:16:13.260
Modified: 2026-01-29T14:16:13.260
Link: CVE-2026-1588
No data.
OpenCVE Enrichment
No data.