Jishenghua JSH_ERP Deserialization Vulnerability in addSerialNumber Endpoint

Vulnerability

A deserialization vulnerability has been identified in Jishenghua JSH_ERP version 2.3.1. The issue arises in the addSerialNumber endpoint, which is susceptible to fastjson deserialization attacks. This vulnerability allows for remote code execution.

Impact

Exploitation of this vulnerability allows for remote code execution on the server where JSH_ERP is running.

Added: Nov 25, 2025, 9:19 PM
Updated: Nov 25, 2025, 10:21 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
8.7
remediation
0.0
relevance
1.1
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.