CVE-2025-10816

CRITICAL WAF: High
CVSS 9.8 Published: 2025-09-22
CWE-611 CWE-611

A security flaw has been discovered in Jinher OA 2.0. This affects an unknown part of the file /c6/Jhsoft.Web.module/ToolBar/GetWordFileName.aspx/?text=GetUrl&style=add of the component XML Handler. Performing manipulation results in xml external entity reference. The attack may be initiated remotely. The exploit has been released to the public and may be exploited.

WAF Coverage Analysis

XML External Entity (XXE) High WAF Coverage

OWASP: A05:2021 Security Misconfiguration

941xxx - XSS / XXE
XML External Entity (XXE) High WAF Coverage

OWASP: A05:2021 Security Misconfiguration

941xxx - XSS / XXE

Affected Software

VendorProductVersion
jinherjinher_oa2.0

References

  • github.com (Exploit, Issue Tracking, Third Party Advisory)
  • vuldb.com (Permissions Required, VDB Entry)
  • vuldb.com (Third Party Advisory, VDB Entry)
  • vuldb.com (Third Party Advisory, VDB Entry)
Back to CVE Database