📦 Xinhu

by Rockoa

🔍 What is Xinhu?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-48930

CRITICAL CVSS 9.8 Dec 6, 2023

CVE-2023-48930 is an unrestricted file upload vulnerability in Xinhu OA 2.2.1 that allows attackers to upload malicious files to the server. This affects all organizations using the vulnerable version...

CVE-2024-57151

MEDIUM CVSS 6.8 Mar 18, 2025

This SQL injection vulnerability in rainrocka xinhu allows remote attackers to execute arbitrary SQL commands via the inputAction.php file's saveAjax function. Attackers can potentially read, modify, ...

CVE-2024-48213

MEDIUM CVSS 4.3 Oct 23, 2024

RockOA v2.6.5 contains a directory traversal vulnerability in the beifenAction.php file that allows attackers to read arbitrary files on the server by manipulating file paths. This affects all systems...

CVE-2024-7327

MEDIUM CVSS 6.3 Jul 31, 2024

This critical SQL injection vulnerability in Xinhu RockOA allows remote attackers to execute arbitrary SQL commands by manipulating the nickName parameter in the dataAction function. This affects all ...

CVE-2024-37623

MEDIUM CVSS 6.1 Jun 17, 2024

Xinhu RockOA v2.6.3 contains a reflected cross-site scripting (XSS) vulnerability in the /kaoqin/tpl_kaoqin_locationchange.html component. This allows attackers to inject malicious scripts that execut...