A security flaw has been discovered in Jinher OA 2.0....
Moderate severity
Unreviewed
Published
Sep 23, 2025
to the GitHub Advisory Database
•
Updated Oct 3, 2025
Description
Published by the National Vulnerability Database
Sep 22, 2025
Published to the GitHub Advisory Database
Sep 23, 2025
Last updated
Oct 3, 2025
A security flaw has been discovered in Jinher OA 2.0. This affects an unknown part of the file /c6/Jhsoft.Web.module/ToolBar/GetWordFileName.aspx/?text=GetUrl&style=add of the component XML Handler. Performing manipulation results in xml external entity reference. The attack may be initiated remotely. The exploit has been released to the public and may be exploited.
References