CVE-2026-84109: Xinhu Rainrock RockOA webmainAction.php getOrder sql injection
A weakness has been identified in Xinhu Rainrock RockOA up to 2.7.6. Affected by this issue is the function getOrder of the file webmain/webmainAction.php. Executing a manipulation of the argument highorder can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
Which deployments are affected?
Xinhu Rainrock RockOA versions up to and including 2.7.6 are affected. The vulnerable code is the getOrder function in webmain/webmainAction.php.
What access does an attacker need?
The attack can be launched remotely and requires low-level privileges. No user interaction is required.
Is exploitation practical?
Public exploit material is available, so the issue could be used in attacks. Successful exploitation can affect confidentiality, integrity, and availability at a low impact level.
Is a vendor fix or response available?
The provided data does not identify a fix. It states that the vendor was contacted before disclosure but did not respond.