Vendor
jshERP 3.6 contains an improper access control vulnerability in the updateOneValueByKeyIdAndType endpoint allowing authenticated users to escalate privileges to tenant administrator.