Sploitus

CVE-2025-63742

2 known exploits for CVE-2025-63742

SQL Injection vulnerability in function setwxqyAction in file webmain/task/api/loginAction.php in Xinhu Rainrock RockOA 2.7.0 allowing attackers gain sensitive information, including administrator accounts, password hashes, database structure, and other critical data via the shouji and userid parameters.

Affected products
Rockoa
Rockoa
= 2.7.0
Fix
Available
CVSS 3.1
9.8 CRITICAL
EPSS
0.4% (33th percentile)
Weakness
CWE-89
NVD status
Analyzed
Published
2025-12-09
CVE-2025-63742 at NVD
Authoritative description, scoring and affected products

2 known exploits for CVE-2025-63742

Proof-of-concept code and exploit modules indexed by Sploitus