A vulnerability was found in Jinher OA up to 1.2. This...
Moderate severity
Unreviewed
Published
Sep 8, 2025
to the GitHub Advisory Database
•
Updated Oct 9, 2025
Description
Published by the National Vulnerability Database
Sep 8, 2025
Published to the GitHub Advisory Database
Sep 8, 2025
Last updated
Oct 9, 2025
A vulnerability was found in Jinher OA up to 1.2. This impacts an unknown function of the file /c6/Jhsoft.Web.projectmanage/TaskManage/AddTask.aspx/?Type=add of the component XML Handler. The manipulation results in xml external entity reference. The attack can be executed remotely. The exploit has been made public and could be used.
References