CVE-2025-9931 Details
Description
A vulnerability was detected in Jinher OA 1.0. Affected is an unknown function of the file /jc6/platform/sys/login!changePassWord.action of the component POST Request Handler. The manipulation of the argument Account results in cross site scripting. The attack can be launched remotely. The exploit is now public and may be used.
A reflected cross-site scripting vulnerability has been identified in Jinher OA version 1.0. The issue resides in the POST request handler for the login!changePassWord.action endpoint. The vulnerability is caused by inadequate input sanitization of the 'Account' parameter in POST requests, allowing remote attackers to inject arbitrary JavaScript payloads. These payloads are executed in the context of the victim's browser, triggered by user interactions such as mouse hovers.
It is recommended to implement proper input validation and sanitization for the 'Account' parameter, rejecting inputs that contain HTML or JavaScript syntax. Additionally, user-controlled data should be encoded before being rendered in HTML to prevent script execution.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Sep 4, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/1276486/CVE/issues/4 | [email protected] | ExploitIssue TrackingThird Party Advisory |
| https://vuldb.com/?ctiid.322333 | [email protected] | Permissions RequiredVDB Entry |
| https://vuldb.com/?id.322333 | [email protected] | Third Party AdvisoryVDB Entry |
| https://vuldb.com/?submit.642997 | [email protected] | Third Party AdvisoryVDB Entry |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| jinher jinher oa | 1.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Oct 9, 2025 | Initial Analysis | [email protected] |
| Sep 4, 2025 | New CVE Received | [email protected] |