Xinhu

Rockoa

8 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.04%
  • Veröffentlicht 09.12.2025 00:00:00
  • Zuletzt bearbeitet 10.12.2025 21:16:04

Cross-site scripting (XSS) vulnerability in function urltestAction in file cliAction.php in Xinhu Rainrock RockOA 2.7.0 allows remote attackers to inject arbitrary web script or HTML via the m parameter to the task.php endpoint.

  • EPSS 0.03%
  • Veröffentlicht 09.12.2025 00:00:00
  • Zuletzt bearbeitet 10.12.2025 22:16:25

An issue was discovered in file index.php in Xinhu Rainrock RockOA 2.7.0 allowing attackers to gain sensitive information via phpinfo via the a parameter to the index.php.

  • EPSS 0.02%
  • Veröffentlicht 09.12.2025 00:00:00
  • Zuletzt bearbeitet 11.12.2025 17:15:56

An issue was discovered in function phpinisaveAction in file webmain/system/cogini/coginiAction.php in Xinhu Rainrock RockOA 2.7.0 allowing attackers to authenticated users to modify PHP configuration files via the a parameter to the index.php endpoi...

  • EPSS 0.02%
  • Veröffentlicht 09.12.2025 00:00:00
  • Zuletzt bearbeitet 10.12.2025 22:16:26

SQL Injection vulnerability in function getselectdataAjax in file inputAction.php in Xinhu Rainrock RockOA 2.7.0 allowing attackers gain sensitive information, including administrator accounts, password hashes, database structure, and other critical ...

  • EPSS 0.01%
  • Veröffentlicht 09.12.2025 00:00:00
  • Zuletzt bearbeitet 11.12.2025 20:16:27

SQL Injection vulnerability in function setwxqyAction in file webmain/task/api/loginAction.php in Xinhu Rainrock RockOA 2.7.0 allowing attackers gain sensitive information, including administrator accounts, password hashes, database structure, and ot...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 29.08.2025 01:02:10
  • Zuletzt bearbeitet 11.09.2025 12:43:41

A vulnerability was found in Xinhu RockOA up to 2.6.9. Impacted is the function publicsaveAjax of the file /index.php. Performing manipulation results in improper authorization. The attack is possible to be carried out remotely. The exploit has been ...

Exploit
  • EPSS 0.17%
  • Veröffentlicht 21.07.2024 05:15:04
  • Zuletzt bearbeitet 21.11.2024 09:50:35

A vulnerability was found in Xinhu RockOA 2.6.3 and classified as problematic. Affected by this issue is the function okla of the file /webmain/public/upload/tpl_upload.html. The manipulation of the argument callback leads to cross site scripting. Th...

Exploit
  • EPSS 0.85%
  • Veröffentlicht 17.06.2024 14:15:11
  • Zuletzt bearbeitet 30.04.2025 23:53:02

Xinhu RockOA v2.6.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the num parameter at /flow/flow.php.