以下是从截图中获取到的关于漏洞的关键信息,简洁地用Markdown格式返回: Title: jshERP v3.6 Path Traversal Description: - Accessing route - Request is sent to handler - User-passed MultipartFile object is passed subsequently to - Function allows uploading any file to the project directory (like a webshell file). Source: https://github.com/jishenghua/jshERP/issues/146 VulDB Entry: 234245 Status: Accepted Points: 20 Submission Date: 01/15/2026 04:23 PM Moderation Date: 01/28/2026 05:53 PM User: mukyuuhate (UID 93052)