BigMancer/Jinhe-OA-XXE-Vulnerability

BigMancer/Jinhe-OA-XXE-Vulnerability

Releases0

CVE History

CVEPublishedCVSS v3CVSS v2
7.3 HIGH7.5 HIGH

A vulnerability was found in Jinher OA 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /c6/Jhsoft.Web.message/ToolBar/DelTemp.aspx. The manipulation leads to xml external entity reference. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.