Skip to main content

CVE detail

CVE-2025-55368

Incorrect access control in the component \controller\RoleController.java of jshERP v3.5 allows unauthorized attackers to arbitrarily modify the supplier status under any account.

CVSS 8.8 · HighBuzz score 25.02 public exploit repository references

Buzz score

Why this CVE is surfacing

Buzz score total 25.0

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 11.0 · diversity 5.0 · KEV 0.0 · OTX 0.0 · PoC 9.0
Mention score
11.0
2 evidence mentions in the snapshot
Diversity score
5.0
1 sources across 1 categories
KEV score
0.0
No KEV entry observed
OTX score
0.0
0 OTX pulses
PoC score
9.0
2 repos · best confidence 0.90
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
2 source links · newest first

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

2 repository references · best confidence 0.90 · max 0 stars
  • jishenghua/jshERPHigh confidence
    githubNVD Exploit reference0 starsDiscovered Aug 11, 2026, 12:20 AM

    NVD labels the source link as Exploit; this is not independent verification of the repository's code.

  • cina666/CVEHigh confidence
    githubNVD Exploit reference0 starsDiscovered Aug 11, 2026, 12:20 AM

    NVD labels the source link as Exploit; this is not independent verification of the repository's code.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence
  • CVE-2025-60800

    Incorrect access control in the /jshERP-boot/user/info interface of jshERP up to commit 90c411a allows attackers to access sensitive information via a crafted GET request.

    CVSS 7.5 · High
    Public PoC observed1 mention
  • CVE-2025-55371

    Incorrect access control in the component /controller/PersonController.java of jshERP v3.5 allows unauthorized attackers to obtain all the information of the handler by executing…

    CVSS 5.3 · Medium
    Public PoC observed2 mentions
  • CVE-2025-55367

    Incorrect access control in the component \controller\SupplierController.java of jshERP v3.5 allows unauthorized attackers to arbitrarily modify the supplier status under any acco…

    CVSS 5.3 · Medium
    Public PoC observed2 mentions
  • CVE-2025-55366

    Incorrect access control in the component \controller\UserController.java of jshERP v3.5 allows attackers to arbitrarily reset user account passwords and execute a horizontal priv…

    CVSS 5.3 · Medium
    Public PoC observed2 mentions
  • CVE-2026-19992

    A flaw has been found in Orange View Limited DualSafe Password Manager & Digital Vault Extension up to 1.4.35 on Chrome. Affected is an unknown function of the component postMessa…

    CVSS 1.3 · Low
    5 mentions
  • CVE-2026-73061

    Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedObjectAccessor that allows template code to write CLR object properties without setter-visibility che…

    CVSS 9.3 · Critical
    2 mentions