216.73.216.226

CVE-2025-10816

· Published 22/09/2025 22:15 · Modified 22/09/2025 22:15

Labels: CVE-2025-10816 2025-09-22CVE-2025-10816CWE-610[email protected]

Essential information

Published
22/09/2025 22:15
Modified
22/09/2025 22:15
Author
Creator
CVSS
6.9 MEDIUM (v3) 6.9 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

A security flaw has been discovered in Jinher OA 2.0. This affects an unknown part of the file /c6/Jhsoft.Web.module/ToolBar/GetWordFileName.aspx/?text=GetUrl&style=add of the component XML Handler. Performing manipulation results in xml external entity reference. The attack may be initiated remotely. The exploit has been released to the public and may be exploited.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
jinher / oa cpe:2.3:a:jinher:oa:2.0:*:*:*:*:*:*:*

References