Junglewise Threat Intelligence

CVE-2026-11435: Jinher OA SQL injection in nextselectplan.aspx

CVE-2026-11435 · Severity: high · CVSS 7.3 · Published 2026-06-06

Executive brief

Jinher OA, an office automation platform used for business management and workflow coordination, contains a security flaw that allows unauthorized individuals to access its database. By sending a specially crafted web request, an attacker can bypass security controls to view sensitive business data or modify system information. This vulnerability requires no login credentials and can be exploited remotely over the internet.

Technical details

A SQL injection vulnerability exists in Jinher OA (Jhsoft OA) version 1.0 within the JHSoft.Web.PlanSummarize/nextselectplan.aspx component. The root cause is the improper neutralization of the 'httpOID' GET parameter, which is directly concatenated into SQL queries without validation or parameterization. An unauthenticated remote attacker can exploit this by sending crafted HTTP requests to execute arbitrary SQL commands against the backend Microsoft SQL Server database. This can result in unauthorized data extraction, modification, or potential remote code execution on the database server. As of the advisory date, the vendor has not responded to disclosure attempts, and no official patch is available.

Affected products

  • Jinher Network OA (Jhsoft OA) 1.0

Timeline

  • 2026-05-07: disclosed: Initial vulnerability report by security researcher Mr-Elymas
  • 2026-06-06: advisory: NVD publication of CVE-2026-11435

References