216.73.216.6

CVE-2025-63742

· Published 09/12/2025 17:15 · Modified 12/12/2025 12:27

Labels: CVE-2025-63742 2025-12-09CVE-2025-63742CWE-89[email protected]

Essential information

Published
09/12/2025 17:15
Modified
12/12/2025 12:27
Author
Creator
CVSS
9.8 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

SQL Injection vulnerability in function setwxqyAction in file webmain/task/api/loginAction.php in Xinhu Rainrock RockOA 2.7.0 allowing attackers gain sensitive information, including administrator accounts, password hashes, database structure, and other critical data via the shouji and userid parameters.

NVD status

Status
Analyzed — CVE has had analysis completed and all data associations made.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
rockoa / rockoa cpe:2.3:a:rockoa:rockoa:2.7.0:*:*:*:*:*:*:*

References