SQL Injection vulnerability in function getselectdataAjax in file inputAction.php in Xinhu Rainrock RockOA 2.7.0 allowing attackers gain sensitive information, including administrator accounts, password hashes, database structure, and other critical data via the actstr parameter.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://github.com/rainrocka/xinhu/issues/13 |
|
History
Wed, 10 Dec 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-89 | |
| Metrics |
cvssV3_1
|
Wed, 10 Dec 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Xinhu
Xinhu rockoa |
|
| Vendors & Products |
Xinhu
Xinhu rockoa |
Tue, 09 Dec 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SQL Injection vulnerability in function getselectdataAjax in file inputAction.php in Xinhu Rainrock RockOA 2.7.0 allowing attackers gain sensitive information, including administrator accounts, password hashes, database structure, and other critical data via the actstr parameter. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-12-09T00:00:00.000Z
Updated: 2025-12-10T21:12:43.640Z
Reserved: 2025-10-27T00:00:00.000Z
Link: CVE-2025-63740
Updated: 2025-12-10T21:12:40.245Z
Status : Undergoing Analysis
Published: 2025-12-09T17:15:55.237
Modified: 2025-12-10T22:16:26.020
Link: CVE-2025-63740
No data.