CVE-2026-50782

high

Description

Jinher OA C6 contains an XML External Entity (XXE) injection vulnerability in the /c6/JHSoft.Web.HrmAttendance/sp_manager_getUserlist.aspx/GetXmlHttp endpoint. An unauthenticated remote attacker can send a crafted XML payload to read arbitrary files from the server via an out-of-band attack.

References

https://github.com/dihe123/CNVD-Jinher-OA-XXE/tree/main

https://github.com/dihe123/CNVD-Jinher-OA-XXE/blob/main/README.md

Details

Source: Mitre, NVD

Published: 2026-07-29

Updated: 2026-07-30

Risk Information

CVSS v2

Base Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:N

Severity: High

CVSS v3

Base Score: 7.5

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Severity: High

EPSS

EPSS: 0.00249