CVE-2025-63739: Medium severity Xinhu Rainrock RockOA vulnerability
An issue was discovered in function phpinisaveAction in file webmain/system/cogini/coginiAction.php in Xinhu Rainrock RockOA 2.7.0 allowing attackers to authenticated users to modify PHP configuration files via the a parameter to the index.php endpoint.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-63739?
CVE-2025-63739 is considered a high severity vulnerability due to its potential to allow authenticated users to alter PHP configuration files.
How do I fix CVE-2025-63739?
To fix CVE-2025-63739, ensure that the application is updated to the latest version where this vulnerability is patched.
Who is affected by CVE-2025-63739?
CVE-2025-63739 affects users of Xinhu Rainrock RockOA version 2.7.0.
What type of vulnerability is CVE-2025-63739?
CVE-2025-63739 is a privilege escalation vulnerability that allows authenticated users to modify critical PHP configuration files.
What does CVE-2025-63739 allow attackers to do?
CVE-2025-63739 allows attackers who are authenticated users to modify PHP configuration files via a parameter in the index.php endpoint.