CVE-2026-84109

Summary

A weakness has been identified in Xinhu Rainrock RockOA up to 2.7.6. Affected by this issue is the function getOrder of the file webmain/webmainAction.php. Executing a manipulation of the argument highorder can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

Affected Software

VendorProductVersion RangeStatus
XinhuRainrock RockOA2.7.0affected
XinhuRainrock RockOA2.7.1affected
XinhuRainrock RockOA2.7.2affected
XinhuRainrock RockOA2.7.3affected
XinhuRainrock RockOA2.7.4affected
XinhuRainrock RockOA2.7.5affected
XinhuRainrock RockOA2.7.6affected

Weaknesses

  • CWE-89: SQL Injection
  • CWE-74: Injection

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: poc
    • Automatable: no
    • Technical Impact: partial

References