CVE-2025-63738: Medium severity Xinhu Rainrock RockOA vulnerability
An issue was discovered in file index.php in Xinhu Rainrock RockOA 2.7.0 allowing attackers to gain sensitive information via phpinfo via the a parameter to the index.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-63738?
CVE-2025-63738 is classified as a high-severity vulnerability due to its potential to expose sensitive information.
How does CVE-2025-63738 affect Xinhu Rainrock RockOA 2.7.0?
CVE-2025-63738 allows attackers to utilize the phpinfo function through a parameter in the index.php file, leading to information disclosure.
What are the potential impacts of CVE-2025-63738?
The potential impact of CVE-2025-63738 includes exposure of sensitive environment information and configuration details that can aid an attacker.
How do I fix CVE-2025-63738?
To fix CVE-2025-63738, ensure that the index.php file does not allow access to the phpinfo function or restrict vulnerable parameters.
Is CVE-2025-63738 present in versions other than 2.7.0 of Xinhu Rainrock RockOA?
CVE-2025-63738 specifically affects version 2.7.0 of Xinhu Rainrock RockOA, and other versions may not be impacted.