/Vulnerability Library

Jinher OA - SQL Injection

CVE-2025-10090
Verified

Description

jinher jinher_oa is an office automation software that facilitates workflow management and collaboration within organizations. It sits in the enterprise layer of the tech stack, is typically deployed as self_hosted, and—within the information_technology industry—serves the business_apps domain.

Severity

High

CVSS Score

7.3

Exploit Probability

2%

Published Date

February 10, 2026

Template Author

dhiyaneshdk

CVE-2025-10090.yaml
7.3Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CVE ID:
cve-2025-10090
CWE ID:
cwe-74, cwe-89

References

https://github.com/Madgeaaaaa/MY_VULN_2/blob/main/D-Link/vuln-2/DIR-803%20Authentication%20Bypass.mdhttps://vuldb.com/?id.335869https://nvd.nist.gov/vuln/detail/CVE-2025-14528

Remediation Steps

Update to the latest version.