CVE-2025-63740

MEDIUM

Xinhu Rainrock RockOA <2.7.0 - SQL Injection

Title source: llm
STIX 2.1

Description

SQL Injection vulnerability in function getselectdataAjax in file inputAction.php in Xinhu Rainrock RockOA 2.7.0 allowing attackers gain sensitive information, including administrator accounts, password hashes, database structure, and other critical data via the actstr parameter.

References (1)

Core 1
Core References
Exploit, Issue Tracking, Third Party Advisory
https://github.com/rainrocka/xinhu/issues/13

Scores

CVSS v3 4.3
EPSS 0.0020
EPSS Percentile 10.2%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (1)
rockoa/rockoa 2.7.0
Published Dec 09, 2025
Tracked Since Feb 18, 2026