CVE-2025-63742

Source
https://cve.org/CVERecord?id=CVE-2025-63742
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-63742.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-63742
Published
2025-12-09T17:15:55.360Z
Modified
2026-03-13T03:40:54.645714Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

SQL Injection vulnerability in function setwxqyAction in file webmain/task/api/loginAction.php in Xinhu Rainrock RockOA 2.7.0 allowing attackers gain sensitive information, including administrator accounts, password hashes, database structure, and other critical data via the shouji and userid parameters.

References

Affected packages

Git /

Affected ranges

Database specific

unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "2.7.0"
            }
        ]
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-63742.json"