Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mmqw-r4v3-63q7

Опубликовано: 26 сент. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 2.1
CVSS3: 6.3

Описание

A vulnerability was determined in Jinher OA 2.0. The impacted element is an unknown function of the file /c6/Jhsoft.Web.module/ToolBar/ManageWord.aspx/?text=GetUrl&style=1. This manipulation causes xml external entity reference. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.

A vulnerability was determined in Jinher OA 2.0. The impacted element is an unknown function of the file /c6/Jhsoft.Web.module/ToolBar/ManageWord.aspx/?text=GetUrl&style=1. This manipulation causes xml external entity reference. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.

EPSS

Процентиль: 4%
0.00019
Низкий

2.1 Low

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-610
CWE-611

Связанные уязвимости

CVSS3: 6.3
nvd
4 месяца назад

A vulnerability was determined in Jinher OA 2.0. The impacted element is an unknown function of the file /c6/Jhsoft.Web.module/ToolBar/ManageWord.aspx/?text=GetUrl&style=1. This manipulation causes xml external entity reference. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.

EPSS

Процентиль: 4%
0.00019
Низкий

2.1 Low

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-610
CWE-611