Cross-Site Scripting Vulnerability in Xinhu Rainrock RockOA Product
CVE-2025-63737
6.1MEDIUM
What is CVE-2025-63737?
A Cross-Site Scripting (XSS) vulnerability has been identified in the Xinhu Rainrock RockOA software, specifically in the urltestAction function located in the cliAction.php file. This flaw allows remote attackers to inject arbitrary web scripts or HTML via the 'm' parameter sent to the task.php endpoint. If exploited, such vulnerabilities can compromise the security of users' data and lead to unauthorized actions within the application.
