Vulnerability Description
Jinher OA C6 contains an XML External Entity (XXE) injection vulnerability in the /c6/JHSoft.Web.HrmAttendance/sp_manager_getUserlist.aspx/GetXmlHttp endpoint. An unauthenticated remote attacker can send a crafted XML payload to read arbitrary files from the server via an out-of-band attack.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/dihe123/CNVD-Jinher-OA-XXE/blob/main/README.md
- https://github.com/dihe123/CNVD-Jinher-OA-XXE/tree/main
FAQ
What is CVE-2026-50782?
CVE-2026-50782 is a vulnerability with a CVSS score of 7.5 (HIGH). Jinher OA C6 contains an XML External Entity (XXE) injection vulnerability in the /c6/JHSoft.Web.HrmAttendance/sp_manager_getUserlist.aspx/GetXmlHttp endpoint. An unauthenticated remote attacker can s...
How severe is CVE-2026-50782?
CVE-2026-50782 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-50782?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.