Impact
The vulnerability exists in the PlanGiveOut.aspx component of Jinher OA 1.0 and allows an attacker to inject arbitrary SQL statements via manipulation of the httpOID query parameter. The flaw results from unsanitized input concatenated directly into a database query, leading to classic SQL injection. A successful exploitation would give the attacker read or write access to the underlying database, enabling data exfiltration, corruption, or disclosure of sensitive information.
Affected Systems
Only Jinher OA 1.0 is listed as affected. The problematic endpoint is the /C6/JHSoft.Web.PlanSummarize/PlanGiveOut.aspx page. No other versions or components are identified in the advisory.
Risk and Exploitability
The CVSS base score of 6.9 indicates medium severity. The EPSS score of less than 1% shows a low probability of widespread exploitation, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the remote nature of the flaw—requiring only a crafted HTTP request to httpOID—makes it straightforward for an attacker to test and potentially exploit the injection, especially if proof‑of‑concept code is publicly available.
OpenCVE Enrichment