CVE-2026-19905: Jinher OA attendance_out_approve.aspx sql injection
A weakness has been identified in Jinher OA 1.0. Impacted is an unknown function of the file /C6/JHSoft.Web.HrmAttendance/attendanceoutapprove.aspx. This manipulation of the argument httpOID causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19905?
The severity of CVE-2026-19905 is rated as high with a score of 7.3.
What type of vulnerability is CVE-2026-19905?
CVE-2026-19905 is a SQL injection vulnerability identified in Jinher OA.
How do I fix CVE-2026-19905?
To fix CVE-2026-19905, it is recommended to sanitize and validate inputs to prevent SQL injection.
Can CVE-2026-19905 be exploited remotely?
Yes, CVE-2026-19905 can be exploited remotely due to its nature as a SQL injection vulnerability.
Which software is affected by CVE-2026-19905?
CVE-2026-19905 affects Jinher OA version 1.0.