Impact
A weakness was identified in the Jinher OA C6 application where manipulation of the queryID argument in the GetFormSn.aspx component allows remote execution of arbitrary SQL code. The vulnerability arises from inadequate input validation on that endpoint, mapping to CWE-74 and CWE-89, and could enable attackers to read, modify, or delete database records, thereby compromising confidentiality, integrity, and potentially availability of data.
Affected Systems
The affected vendor is Jinher and the product is Jinher OA C6. No specific sub‑versions are listed; the vulnerability applies to all deployments that include the unpatched GetFormSn.aspx functionality.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack can be performed remotely with public exploit code available, requiring no special privileges, which raises the risk of exploitation in exposed environments.
OpenCVE Enrichment