CVE-2025-51742 | jishenghua JSH_ERP 2.3.1 Endpoint getMaterialEnableSerialNumberList parseObject Query deserialization
A vulnerability was found in jishenghua JSH_ERP 2.3.1. It has been declared as critical. Affected by this vulnerability is the function parseObject of the file /material/getMaterialEnableSerialNumberList of the component Endpoint. Such manipulation of the argument Query leads to deserialization.
This vulnerability is uniquely identified as CVE-2025-51742. The attack can be launched remotely. No exploit exists.