CVE-2025-9602: Xinhu RockOA index.php publicsaveAjax improper authorization
Published Aug 29, 2025
·Updated
A vulnerability was found in Xinhu RockOA up to 2.6.9. Impacted is the function publicsaveAjax of the file /index.php. Performing manipulation results in improper authorization. The attack is possible to be carried out remotely. The exploit has been made public and could be used.
Affected Software
2 affected components
Xinhu RockOA<=2.6.9
Rockoa RockOA<=2.6.9
Event History
Aug 29, 2025
CVE Published
via MITRE·01:02 AM
Data Sourced
via MITRE·01:02 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeaknessAffected Software
Feb 27, 57989
Event
via FIRST·11:53 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-9602?
CVE-2025-9602 is rated as a medium-severity vulnerability affecting Xinhu RockOA.
2
How do I fix CVE-2025-9602?
To fix CVE-2025-9602, upgrade Xinhu RockOA to a version later than 2.6.9, where the vulnerability has been patched.
3
What type of vulnerability is CVE-2025-9602?
CVE-2025-9602 is an improper authorization vulnerability allowing remote exploitation.
4
What versions of Xinhu RockOA are affected by CVE-2025-9602?
CVE-2025-9602 affects all versions of Xinhu RockOA up to and including 2.6.9.
5
Can CVE-2025-9602 be exploited remotely?
Yes, CVE-2025-9602 can be exploited remotely, making it a significant security concern.