CVE Details
Basic Information
| Title | Jinher OA ProjectScheduleDelete.aspx xml external entity reference |
|---|---|
| Type | cve |
| Published | 2025-07-19T12:44:06.138Z |
| Modified | 2025-07-19T12:44:06.138Z |
Product Information
| Vendor | Jinher |
|---|---|
| Product | OA |
| Version | 1.2 |
CVSS Information
| Base Score | 6.9 (MEDIUM) |
|---|---|
| Attack Vector | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P |
AI Analysis
| AI Description | A vulnerability in Jinher OA 1.2 allows remote attackers to exploit an XML external entity reference in ProjectScheduleDelete.aspx, potentially leading to data exposure or unauthorized access. |
|---|---|
| AI Severity | Medium |
| AI Vendor | Jinher |
| AI Product | Jinher OA |
| AI Version | 1.2 |
Affected Products
- Jinher OA 1.2
Additional Information
| CWE List | CWE-611, CWE-610 |
|---|---|
| Source | VulDB |
Description
A vulnerability was found in Jinher OA 1.2. It has been declared as problematic. This vulnerability affects unknown code of the file ProjectScheduleDelete.aspx. The manipulation leads to xml external entity reference. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.