VulnerabilityAnalyzed
CVE-2025-10816
The attack may be initiated remotely.
MEDIUM 5.5EPSS 0.55%
Does this matter?
Lower severity and a low EPSS score (0.55%). Track it; it rarely justifies an emergency change on its own.
Description
A security flaw has been discovered in Jinher OA 2.0. This affects an unknown part of the file /c6/Jhsoft.Web.module/ToolBar/GetWordFileName.aspx/?text=GetUrl&style=add of the component XML Handler. Performing manipulation results in xml external entity reference. The attack may be initiated remotely. The exploit has been released to the public and may be exploited.
- CVSS 4.0
- 5.5 MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.55% probability · 44th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-610, CWE-611
- Affected
- jinher/jinher oa
- Source
- cna@vuldb.com
References
- https://github.com/1296299554/CVE/issues/1Exploit, Issue Tracking, Third Party Advisory
- https://vuldb.com/?ctiid.325174Permissions Required, VDB Entry
- https://vuldb.com/?id.325174Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.654466Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.