CVE-2025-11035

MEDIUM

Jinher OA 2.0 - SSRF

Title source: llm

Description

A vulnerability was determined in Jinher OA 2.0. The impacted element is an unknown function of the file /c6/Jhsoft.Web.module/ToolBar/ManageWord.aspx/?text=GetUrl&style=1. This manipulation causes xml external entity reference. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.

Scores

CVSS v3 6.3
EPSS 0.0003
EPSS Percentile 7.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Classification

CWE
CWE-611 CWE-610
Status published

Affected Products (1)

jinher/jinher_oa

Timeline

Published Sep 26, 2025
Tracked Since Feb 18, 2026