Vendor
high
threat
Remote SQL Injection Vulnerability in Jinher OA 1.0 (CVE-2026-15517)
1 rule 2 TTPs 1 CVE 5 IOCsA remote SQL injection vulnerability, CVE-2026-15517, has been discovered in Jinher OA 1.0, allowing unauthenticated attackers to execute arbitrary SQL commands by manipulating the `httpOID` argument in the `/C6/JHSoft.Web.PlanSummarize/PlanGiveOut.aspx` file, with a public exploit available.
exploited
OA 1.0
sql-injection
web-application
vulnerability
cve
remote-code-execution
1r
2t
1c
5i
high
threat
Jinher OA 1.0 SQL Injection Vulnerability (CVE-2026-7670)
2 rules 1 TTP 1 CVEJinher OA 1.0 is vulnerable to remote SQL injection via the DeptIDList parameter in the /C6/JHSoft.Web.PlanSummarize/UserSel.aspx file, potentially allowing attackers to execute arbitrary SQL queries.
OA 1.0
sql-injection
cve-2026-7670
web-application
2r
1t
1c