← Back

CVE-2025-63740

nvd nist
Published: Dec 9, 2025Modified: Jun 17, 2026

JSON object

Loading...
4.3
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 2.8 / Impact: 1.4
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

SQL Injection vulnerability in function getselectdataAjax in file inputAction.php in Xinhu Rainrock RockOA 2.7.0 allowing attackers gain sensitive information, including administrator accounts, password hashes, database structure, and other critical data via the actstr parameter.

Affected (1)

Products: Rockoa: Rockoa
1 product
Rockoa
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 2.7.0

References (1)

Source: cve@mitre.org
ExploitIssue TrackingThird Party Advisory

Timeline

No history available yet.