Executive brief
Jinher OA is an office automation platform used to manage employee workflows and data. A SQL injection vulnerability in the attendance approval module allows unauthenticated attackers to send crafted web requests that bypass database security and execute arbitrary SQL commands, potentially exposing sensitive employee records, business data, and enabling complete system compromise without requiring a password or valid credentials.
Technical details
The vulnerability is a classic SQL injection (CWE-89) in the attendance_out_approve.aspx component of Jinher OA 1.0. The 'httpOID' parameter is directly concatenated into SQL queries without parameterization or input validation, allowing attackers to inject arbitrary SQL syntax. Attack vector is HTTP GET requests over the network; no authentication is required. An unauthenticated remote attacker can craft a malicious URL with SQL payload in the httpOID parameter (e.g., inserting WAITFOR delays or UNION-based queries) to extract database contents, modify data, or achieve remote code execution on the SQL Server backend. Proof-of-concept code using sqlmap has been publicly released. No patch has been reported; the vendor did not respond to early disclosure.
Affected products
- Jinher Network OA 1.0
Timeline
- 2026-06-26: disclosed: SQL injection vulnerability reported on GitHub
- 2026-08-15: disclosed: Published in NVD
- 2026-08-15: other: Exploit made available to the public