Jinher OA - SQL Injection
CVE-2025-10090
Verified
Description
jinher jinher_oa is an office automation software that facilitates workflow management and collaboration within organizations. It sits in the enterprise layer of the tech stack, is typically deployed as self_hosted, and—within the information_technology industry—serves the business_apps domain.
Severity
High
CVSS Score
7.3
Exploit Probability
2%
Published Date
February 10, 2026
Template Author
dhiyaneshdk
CVE-2025-10090.yaml
7.3Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CVE ID:
cve-2025-10090
CWE ID:
cwe-74, cwe-89
Remediation Steps
Update to the latest version.