ZeroHour

CVE-2025-63740

PoC
CVSS 3.1
4.3 medium
EPSS
<1%p13
Published
()
Modified
Description

SQL Injection vulnerability in function getselectdataAjax in file inputAction.php in Xinhu Rainrock RockOA 2.7.0 allowing attackers gain sensitive information, including administrator accounts, password hashes, database structure, and other critical data via the actstr parameter.

Vendors
rockoa
Products
rockoa
Weakness
CWE-89
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.