← back
CVE-2025-10092

Jinher OA XML Type xml external entity reference

CVSS 6.9 MEDIUMEPSS 0.5%CWE-610CWE-611
A vulnerability was found in Jinher OA up to 1.2. This impacts an unknown function of the file /c6/Jhsoft.Web.projectmanage/TaskManage/AddTask.aspx/?Type=add of the component XML Handler. The manipulation results in xml external entity reference. The attack can be executed remotely. The exploit has been made public and could be used.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Affected products
Jinher · OA

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →