---
id: CVE-2025-10091
title: A vulnerability has been found in Jinher OA up to 1.2
summary: >-
  A vulnerability has been found in Jinher OA up to 1.2. This affects an unknown
  function of the file
  /c6/Jhsoft.Web.projectmanage/ProjectManage/XmlHttp.aspx/?Type=add of the
  component XML Handler. The manipulation leads to xml external en…
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-610
  - CWE-611
  - CWE-611
vendor: jinher
product: jinher_oa
affected:
  - jinher_oa <= 1.2
published: '2025-09-08'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T23:10:00.237'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-10091'
references:
  - url: 'https://github.com/Cstarplus/CVE/issues/2'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.323046'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.323046'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.644864'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.00549
epssPercentile: 0.43826
ingestedAt: '2026-09-30T23:29:32.372Z'
---

## Overview

A vulnerability has been found in Jinher OA up to 1.2. This affects an unknown function of the file /c6/Jhsoft.Web.projectmanage/ProjectManage/XmlHttp.aspx/?Type=add of the component XML Handler. The manipulation leads to xml external entity reference. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.

## Affected

- `jinher_oa <= 1.2`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
