GHSA-73pr-pmq3-3g3wMediumCVSS 5.0

jshERP through 3.6 contains a tenant isolation bypass vulnerability that allows authenticated...

Published
September 21, 2026
Last Modified
September 21, 2026

🔗 CVE IDs covered (1)

📋 Description

jshERP through 3.6 contains a tenant isolation bypass vulnerability that allows authenticated users to read other tenants' records via the GET /tenant/info endpoint. Attackers can iterate the primary key to enumerate and access sensitive tenant data including login names, validity dates, user quotas, and enabled state across all platform tenants.

🔗 References (6)