CVE-2025-11035Medium· 6.3▾ SunlitA vulnerability was determined in Jinher OA 2.0. The impacted element is an unknown function of the file /c6/Jhsoft.Web.module/ToolBar/ManageWord.aspx/?text=GetUrl&style=1. This manipulation causes xml external entity reference. The atta…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 34.7 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
A vulnerability was determined in Jinher OA 2.0. The impacted element is an unknown function of the file /c6/Jhsoft.Web.module/ToolBar/ManageWord.aspx/?text=GetUrl&style=1. This manipulation causes xml external entity reference. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.
jinher_oa = 2.0Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-11341High· 7.3A security flaw has been discovered in Jinher OA up to 2.0
CVE-2025-10091High· 7.3A vulnerability has been found in Jinher OA up to 1.2
CVE-2025-11140High· 7.3A vulnerability was identified in Bjskzy Zhiyou ERP up to 11.0
CVE-2022-37911Low· 3.8Due to improper restrictions on XML entities multiple vulnerabilities exist in the command line interface of ArubaOS
CVE-2025-13209Medium· 6.3A weakness has been identified in bestfeng oa_git_free up to 9.5
CVE-2019-3773Critical· 9.8Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.