Impact
Jinher OA C6 contains a CWE‑611 XML External Entity injection flaw in the /c6/JHSoft.Web.HrmAttendance/sp_manager_getUserlist.aspx/GetXmlHttp endpoint. An attacker who is not authenticated can send a crafted XML document that causes the application to resolve external entities, enabling the reading of arbitrary files on the server. This can expose sensitive configuration files, user data, or code, leading to a confidentiality breach.
Affected Systems
All installations of Jinher OA C6 that expose the /c6/JHSoft.Web.HrmAttendance/sp_manager_getUserlist.aspx/GetXmlHttp endpoint are affected. The CVE data does not provide specific patch versions or a detailed vulnerable product range, so every instance of the application that implements this endpoint should be evaluated for the presence of the XML parser’s external entity support.
Risk and Exploitability
The flaw scores a CVSS of 7.5, indicating high severity. The EPSS score is less than 1%, suggesting that active exploitation is currently unlikely, and the vulnerability is not listed in the CISA KEV catalog. The ability to read arbitrary files remotely without authentication represents a significant risk. An attacker needs network access to the application endpoint and the ability to submit XML payloads; the exploitation path is straightforward, requiring no additional credentials or privilege escalation.
OpenCVE Enrichment