CVE-2026-2963

A vulnerability was determined in Jinher OA C6 up to 20260210. This issue affects some unknown processing of the file /C6/Jhsoft.Web.officesupply/OfficeSupplyTypeRight.aspx. This manipulation of the argument id/offsnum causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. It is suggested to install a patch to address this issue. The vendor was contacted early about this disclosure but did not respond in any way.
Configurations

No configuration.

History

23 Feb 2026, 18:13

Type Values Removed Values Added
Summary
  • (es) Se detectó una vulnerabilidad en Jinher OA C6 hasta 20260210. El problema afecta a algún procesamiento desconocido del archivo /C6/Jhsoft.Web.officesupply/OfficeSupplyTypeRight.aspx. Si se manipula el argumento id/offsnum se provoca una inyección SQL. Es posible iniciar el ataque en remoto. El exploit ha sido divulgado públicamente y puede ser utilizado. Se sugiere instalar un parche para abordar este problema. El proveedor fue contactado con antelación sobre esta divulgación pero no respondió de ninguna manera.

23 Feb 2026, 01:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-23 01:16

Updated : 2026-02-23 18:13


NVD link : CVE-2026-2963

Mitre link : CVE-2026-2963

CVE.ORG link : CVE-2026-2963


JSON object : View

Products Affected

No product.

CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')