5.3
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
Description
A vulnerability was detected in Jinher OA 1.0. Affected is an unknown function of the file /jc6/platform/sys/login!changePassWord.action of the component POST Request Handler. The manipulation of the argument Account results in cross site scripting. The attack can be launched remotely. The exploit is now public and may be used.
Basic Information
ID
CVE-2025-9931
Source
VulDB
Published
Sep 3, 2025 at 22:02
Affected Product
Vendor
Jinher
Product
OA
Version
1.0
Affected Versions
Jinher OA 1.0