CVE-2025-10092
Published: 08 September 2025
Summary
CVE-2025-10092 is a medium-severity Externally Controlled Reference to a Resource in Another Sphere (CWE-610) vulnerability in Jinher Jinher Oa. Its CVSS base score is 5.5 (Medium).
Operationally, exploitation aligns with the MITRE ATT&CK technique Data from Local System (T1005); ranked at the 21.9th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2025-27123
Vulnerability details
A vulnerability was found in Jinher OA up to 1.2. This impacts an unknown function of the file /c6/Jhsoft.Web.projectmanage/TaskManage/AddTask.aspx/?Type=add of the component XML Handler. The manipulation results in xml external entity reference. The attack can be executed remotely. The exploit…
more
has been made public and could be used.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise TechniquesAI
Why these techniques?
XXE vulnerability enables remote exploitation of public-facing web app (T1190), arbitrary local file reads for data collection (T1005) and unsecured credentials (T1552.001), SSRF for internal network service discovery (T1046), and OOB data exfiltration over HTTP (T1041).
Affected Assets
Mitigating Controls
Likely Mitigating Controls AI
Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.
Penetration testing includes XML external entity payloads, detecting XXE vulnerabilities and enabling their mitigation.
Limits impact of an externally controlled reference to a primary information resource by switching to an identified alternative.
Identifies XML external entity processing via monitoring of unusual file/network access or resource usage.