Jishenghua JSH_ERP Deserialization Vulnerability in addSerialNumber Endpoint
Vulnerability
A deserialization vulnerability has been identified in Jishenghua JSH_ERP version 2.3.1. The issue arises in the addSerialNumber endpoint, which is susceptible to fastjson deserialization attacks. This vulnerability allows for remote code execution.
Impact
Exploitation of this vulnerability allows for remote code execution on the server where JSH_ERP is running.
Added: Nov 25, 2025, 9:19 PM
Updated: Nov 25, 2025, 10:21 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
10.0exploitability
8.7remediation
0.0relevance
1.1threat
6.4urgency
2.9incentive
5.8Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
