VYPR

Rockoa

by WordPress

CVEs (1)

  • CVE-2025-63742Dec 9, 2025
    risk 0.00cvss epss 0.00

    SQL Injection vulnerability in function setwxqyAction in file webmain/task/api/loginAction.php in Xinhu Rainrock RockOA 2.7.0 allowing attackers gain sensitive information, including administrator accounts, password hashes, database structure, and other critical data via the shouji and userid parameters.