CVE-2025-63742: SQL Injection
SQL Injection vulnerability in function setwxqyAction in file webmain/task/api/loginAction.php in Xinhu Rainrock RockOA 2.7.0 allowing attackers gain sensitive information, including administrator accounts, password hashes, database structure, and other critical data via the shouji and userid parameters.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-63742?
CVE-2025-63742 is considered a high-severity SQL Injection vulnerability.
How do I fix CVE-2025-63742?
To fix CVE-2025-63742, validate and sanitize all user inputs in the setwxqyAction function.
What software is affected by CVE-2025-63742?
CVE-2025-63742 affects version 2.7.0 of Xinhu Rainrock RockOA.
What type of attack does CVE-2025-63742 enable?
CVE-2025-63742 enables attackers to perform SQL Injection attacks to access sensitive information.
What information can be exposed due to CVE-2025-63742?
CVE-2025-63742 can expose sensitive information including administrator accounts, password hashes, and database structure.