CVE 9.8 CRITICAL

CVE-2025-63742_CVE-2025-63742

9.8 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

SQL Injection vulnerability in function setwxqyAction in file webmain/task/api/loginAction.php in Xinhu Rainrock RockOA 2.7.0 allowing attackers gain sensitive information, including administrator accounts, password hashes, database structure, and other critical data via the shouji and userid parameters.

AI Analysis

SQL Injection vulnerability allowing attackers to gain sensitive information

Basic Information

ID CVE-2025-63742
Source mitre
Published Dec 9, 2025 at 00:00
Modified Dec 11, 2025 at 19:16

Affected Product

Vendor Xinhu Rainrock
Product RockOA
Version 2.7.0
Affected Versions n/a n/a n/a

CWE Classification

AI Assessment

AI Score 9.8 / 10
AI Severity Critical
Vendor Xinhu Rainrock
Product RockOA
Version 2.7.0

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.