PT-2025-50097 · Rockoa · Rockoa

Published

2025-12-09

·

Updated

2025-12-22

·

CVE-2025-63738

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Xinhu Rainrock RockOA version 2.7.0
Description An issue exists in the index.php file of Xinhu Rainrock RockOA version 2.7.0 that allows attackers to obtain sensitive information. This is achieved by exploiting the phpinfo function through the a parameter within the index.php file. The a parameter is a vulnerable variable used in the request to the ''index.php'' endpoint.
Recommendations Update to a newer version of Xinhu Rainrock RockOA that addresses this issue. As a temporary workaround, restrict access to the index.php file. Avoid using the a parameter in the ''index.php'' endpoint until the issue is resolved.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-63738

Affected Products

Rockoa