
VulDB advisory: jshERP authenticated /user/info IDOR and password-digest replay after CVE-2025-60800
/user/info IDOR — VulDB submission packageThis repository contains a standalone VulDB-style advisory for an authenticated insecure direct object reference in jshERP.
ad6cf886dd4e0676723060a25d361c703dc56bc0 (3.6-SNAPSHOT, GitHub master HEAD on 2026-09-04)This is not a duplicate of CVE-2025-60800. That CVE covers unauthenticated path-traversal access to /user/info. This report covers the remaining authenticated object-level authorization failure after that filter was patched.
Use as the submission body. When filing:
VULDB_REPORT.mdAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H (8.8)Lab-only changes (captcha flag, a non-default target digest, and allowPublicKeyRetrieval=true) are documented in the report and are not part of the vulnerable source path.