CNNVD-202509-1096 Information

CNNVD ID

CNNVD-202509-1096

CVE-2025-10092

  • CNNVD Published: 2025-09-08

Description (Chinese)

Jinher OA是中国金和(Jinher)公司的一款协同管理软件。 Jinher OA 1.2及之前版本存在代码问题漏洞,该漏洞源于XML处理程序组件中存在XML外部实体引用。

Description (English)

Jinher OA is a co-management software from Jinher China. There is a code gap in Jinher OA 1.2 and earlier versions, which stems from the presence of an XML external entity reference in the XML processor component.

Hazard Level

Medium

Vulnerability Type

代码问题

Published

2025-09-08

Last Modified

2026-02-24

References

https://vuldb.com/?ctiid.323047 https://github.com/Cstarplus/CVE/issues/3 https://vuldb.com/?submit.644868 https://vuldb.com/?id.323047 https://access.redhat.com/security/cve/cve-2025-10092

Share on: