Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
jsherp-user-info-idor — VulDB advisory: jshERP authenticated /user/info IDOR and password-digest replay after CVE-2025-60800 | Kitploit
Tools/GitHubGitHub/bob-wentao/jsherp-user-info-idor
Vulnerability AnalysisExploitationInformation GatheringWeb SecurityPenetration Testing
GitHubbob-wentao/jsherp-user-info-idor

jsherp-user-info-idor

VulDB advisory: jshERP authenticated /user/info IDOR and password-digest replay after CVE-2025-60800

View Repository
1020 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

jshERP /user/info IDOR — VulDB submission package

This repository contains a standalone VulDB-style advisory for an authenticated insecure direct object reference in jshERP.

  • Product: jshERP
  • Tested commit: ad6cf886dd4e0676723060a25d361c703dc56bc0 (3.6-SNAPSHOT, GitHub master HEAD on 2026-09-04)
  • Advisory: VULDB_REPORT.md
  • Local PoC: poc.sh

This is not a duplicate of CVE-2025-60800. That CVE covers unauthenticated path-traversal access to /user/info. This report covers the remaining authenticated object-level authorization failure after that filter was patched.

VulDB submission notes

Use as the submission body. When filing:

VULDB_REPORT.md
  1. Vulnerability type: Insecure Direct Object Reference
  2. CWE: CWE-639, CWE-522
  3. CVSS 3.1: AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H (8.8)
  4. Related record: CVE-2025-60800 — incomplete fix / residual IDOR
  5. Do not describe this as unauthenticated access

Lab-only changes (captcha flag, a non-default target digest, and allowPublicKeyRetrieval=true) are documented in the report and are not part of the vulnerable source path.

Download Tool