CVE-2025-7948
BaseFortify
Publication date: 2025-07-22
Last updated on: 2026-04-29
Assigner: VulDB
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| jishenghua | jsherp | to 3.5 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-640 | The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability in jshERP up to version 3.5 affects an unknown functionality in the file /jshERP-boot/user/updatePwd. It allows an attacker to manipulate the password recovery process, resulting in weak password recovery. The attack can be performed remotely and the exploit has been publicly disclosed.
How can this vulnerability impact me? :
The vulnerability can lead to weak password recovery, which may allow attackers to gain unauthorized access to user accounts by exploiting the password recovery mechanism remotely. This could compromise account security and potentially lead to further unauthorized actions within the affected system.