Metrics
Affected Vendors & Products
Thu, 09 Oct 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:jinher:jinher_oa:*:*:*:*:*:*:*:* |
Tue, 09 Sep 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jinher
Jinher jinher Oa |
|
| Vendors & Products |
Jinher
Jinher jinher Oa |
Mon, 08 Sep 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 08 Sep 2025 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been found in Jinher OA up to 1.2. This affects an unknown function of the file /c6/Jhsoft.Web.projectmanage/ProjectManage/XmlHttp.aspx/?Type=add of the component XML Handler. The manipulation leads to xml external entity reference. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. | |
| Title | Jinher OA XML Type xml external entity reference | |
| Weaknesses | CWE-610 CWE-611 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2025-09-08T11:02:06.958Z
Updated: 2025-09-08T13:38:24.967Z
Reserved: 2025-09-08T04:57:59.525Z
Link: CVE-2025-10091
Updated: 2025-09-08T13:38:15.753Z
Status : Analyzed
Published: 2025-09-08T11:15:30.870
Modified: 2025-10-09T18:49:48.293
Link: CVE-2025-10091
No data.