What is CVE-2026-19905?
A SQL injection vulnerability has been identified in Jinher OA 1.0 via the 'httpOID' parameter in the '/C6/JHSoft.Web.HrmAttendance/attendance_out_approve.aspx' file. This allows a remote attacker to perform unauthorized database queries. Updating to the latest version and enforcing strict input validation are recommended.
Azərbaycanca: Jinher OA 1.0 sistemində '/C6/JHSoft.Web.HrmAttendance/attendance_out_approve.aspx' faylındakı 'httpOID' parametri vasitəsilə SQL injection zəifliyi aşkar edilib. Bu, uzaqdan hücum edən şəxsə verilənlər bazasına icazəsiz sorğular göndərməyə imkan verir. Sistemin son versiyasına yenilənməsi və daxil olan parametrlərin ciddi validasiyası tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Where is the SQL injection vulnerability CVE-2026-19905 located in Jinher OA 1.0?
The vulnerability is found in the 'httpOID' parameter within the '/C6/JHSoft.Web.HrmAttendance/attendance_out_approve.aspx' file.
What can a remote attacker gain by exploiting CVE-2026-19905?
A remote attacker can perform unauthorized database queries.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.