A vulnerability was found in jshERP 3.3 and classified as problematic. This issue affects some unknown processing of the file jshERP-boot/systemConfig/upload. The manipulation of the argument biz leads to unrestricted upload.
The identification of this vulnerability is CVE-2024-24000. The attack can only be initiated within the local network. There is no exploit available.