CNNVD-202507-2512 Information

CNNVD ID

CNNVD-202507-2512

CVE-2025-7824

  • CNNVD Published: 2025-07-19

Description (Chinese)

Jinher OA是中国金和(Jinher)公司的一款协同管理软件。 Jinher OA 1.1版本存在代码问题漏洞,该漏洞源于对文件XmlHttp.aspx的错误操作导致XML外部实体引用。

Description (English)

Jinher OA is a co-management software from Jinher China. There is a code gap in version Jinher OA 1.1, which stems from an error in the file XmlHtttp.aspx that led to an external XML reference.

Hazard Level

Medium

Vulnerability Type

代码问题

Published

2025-07-19

Last Modified

2026-02-24

References

https://github.com/cc2024k/CVE/issues/2 https://vuldb.com/?id.316925 https://vuldb.com/?submit.616842 https://vuldb.com/?ctiid.316925 https://nvd.nist.gov/vuln/detail/CVE-2025-7824

Share on: