MikeTrendsTrends right now

Mmastodon TechnologyCybersecurity first seen 2 h ago, last 2 h ago, peak #9

jshERP flaw leaks MD5 password hashes, remains unpatched

Original: CVE-2026-94413: jshERP through 3.6 leaks unsalted MD5 password hashes via /user/info, enabling offline cracking and auth

A newly published vulnerability, CVE-2026-94413, affects jshERP versions through 3.6. The /user/info endpoint exposes unsalted MD5 password hashes, which attackers could crack offline and replay to bypass authentication. The flaw carries a CVSS score of 6.5 and currently has no vendor patch. Security practitioners are urging administrators to restrict access to the affected endpoint as an interim measure while waiting for an official fix.

Why now: A newly disclosed, unpatched vulnerability affecting a widely used ERP system is being circulated so administrators can mitigate it before exploitation.

jshERPCVE-2026-94413

Open on mastodon →

Evidence

API: https://socialmediatrends-api.osmike.com/v1/trends/1457296