PT-2025-35847 · Jinher Oa · Jinher Oa

Zre0X1C

·

Published

2025-09-03

·

Updated

2025-10-09

·

CVE-2025-9931

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Jinher OA version 1.0
Description A cross site scripting issue exists due to the manipulation of the Account argument. The issue affects an unknown function within the file /jc6/platform/sys/login!changePassWord.action of the POST Request Handler component. The attack can be launched remotely. The exploit is now public.
Recommendations As a temporary workaround, consider restricting access to the /jc6/platform/sys/login!changePassWord.action endpoint until a fix is available. Sanitize the Account argument to prevent the injection of malicious scripts.

Exploit

Fix

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-9931

Affected Products

Jinher Oa