CVE-2026-50782
Deferred Deferred - Pending Action

Jinher OA C6 XML External Entity Injection Vulnerability

Vulnerability report for CVE-2026-50782, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-29

Last updated on: 2026-07-30

Assigner: MITRE

Description

Jinher OA C6 contains an XML External Entity (XXE) injection vulnerability in the /c6/JHSoft.Web.HrmAttendance/sp_manager_getUserlist.aspx/GetXmlHttp endpoint. An unauthenticated remote attacker can send a crafted XML payload to read arbitrary files from the server via an out-of-band attack.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-29
Last Modified
2026-07-30
Generated
2026-08-19
AI Q&A
2026-07-30
EPSS Evaluated
2026-08-18
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
jinher oa_c6 *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-611 The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Jinher OA C6 has an XML External Entity (XXE) injection vulnerability in the /c6/JHSoft.Web.HrmAttendance/sp_manager_getUserlist.aspx/GetXmlHttp endpoint. This allows an unauthenticated remote attacker to send a specially crafted XML payload to read arbitrary files from the server using an out-of-band attack.

Detection Guidance

To detect this XXE vulnerability in Jinher OA C6, scan for requests to the vulnerable endpoint /c6/JHSoft.Web.HrmAttendance/sp_manager_getUserlist.aspx/GetXmlHttp. Use tools like Burp Suite or OWASP ZAP to intercept and inspect XML payloads sent to this path. Check server logs for unusual file read attempts or out-of-band network connections.

Impact Analysis

An attacker could exploit this to access sensitive files on the server, potentially exposing confidential data such as system files, user credentials, or other sensitive information stored on the system.

Compliance Impact

This vulnerability could lead to unauthorized data access, violating compliance requirements under GDPR (data protection) and HIPAA (health information privacy), potentially resulting in legal penalties and reputational damage.

Mitigation Strategies

Immediately apply patches or updates from Jinher to fix the XXE vulnerability. If patches are unavailable, disable the vulnerable endpoint /c6/JHSoft.Web.HrmAttendance/sp_manager_getUserlist.aspx/GetXmlHttp. Configure firewalls to block external access to this endpoint. Monitor network traffic for suspicious XML payloads.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-50782. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart