📦 Rockoa

by Rockoa

🔍 What is Rockoa?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-63742

CRITICAL CVSS 9.8 Dec 9, 2025

This SQL injection vulnerability in Xinhu Rainrock RockOA allows attackers to execute arbitrary SQL commands through the shouji and userid parameters. Attackers can extract sensitive data including ad...

CVE-2023-49363

CRITICAL CVSS 9.8 Dec 13, 2023

CVE-2023-49363 is a critical SQL injection vulnerability in Rockoa versions before 2.3.3 that allows attackers to execute arbitrary SQL commands. This affects all organizations using vulnerable Rockoa...

CVE-2020-18714

CRITICAL CVSS 9.8 Feb 5, 2021

CVE-2020-18714 is a critical SQL injection vulnerability in Rockoa v1.8.7 that allows remote attackers to execute arbitrary SQL commands through the wordModel.php file. This can lead to privilege esca...

CVE-2020-18716

CRITICAL CVSS 9.8 Feb 5, 2021

CVE-2020-18716 is a critical SQL injection vulnerability in Rockoa v1.8.7 that allows remote attackers to execute arbitrary SQL commands through insufficient parameter filtering in wordAction.php. Thi...

CVE-2020-20593

HIGH CVSS 8.0 Dec 22, 2021

This CSRF vulnerability in Rockoa v1.9.8 allows authenticated attackers to create unauthorized administrator accounts by tricking legitimate users into submitting malicious requests. It affects all Ro...

CVE-2025-63738

MEDIUM CVSS 4.3 Dec 9, 2025

This vulnerability in Xinhu Rainrock RockOA 2.7.0 allows attackers to access sensitive system information through the phpinfo() function by manipulating the 'a' parameter in index.php. This affects al...

CVE-2025-63739

MEDIUM CVSS 4.3 Dec 9, 2025

This vulnerability allows authenticated users in Xinhu Rainrock RockOA 2.7.0 to modify PHP configuration files through a specific endpoint. Attackers could alter PHP settings to weaken security contro...

CVE-2025-63740

MEDIUM CVSS 4.3 Dec 9, 2025

This SQL injection vulnerability in Xinhu Rainrock RockOA 2.7.0 allows attackers to execute arbitrary SQL commands via the actstr parameter in the getselectdataAjax function. Attackers can extract sen...

CVE-2025-63737

MEDIUM CVSS 6.1 Dec 9, 2025

A cross-site scripting (XSS) vulnerability in Xinhu Rainrock RockOA 2.7.0 allows attackers to inject malicious scripts via the 'm' parameter in the task.php endpoint. This affects all users of RockOA ...