XML External Entity Reference Vulnerability in Jinher OA Product by Jinher Technology
CVE-2025-7823
Key Information:
Badges
What is CVE-2025-7823?
A vulnerability exists in Jinher OA version 1.2, specifically in the ProjectScheduleDelete.aspx file. This security flaw allows attackers to manipulate XML external entity references, enabling remote exploits that could compromise the integrity and confidentiality of the application. The exposure has been publicly disclosed, emphasizing the necessity for immediate remedial action to mitigate potential risks associated with unauthorized access and data breaches.
Affected Version(s)
OA 1.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved