PHP Configuration File Modification Vulnerability in Xinhu Rainrock
CVE-2025-63739
4.3MEDIUM
What is CVE-2025-63739?
A vulnerability in the function phpinisaveAction located in webmain/system/cogini/coginiAction.php enables authenticated users to modify sensitive PHP configuration files by manipulating parameters within the index.php endpoint. This flaw can lead to unauthorized changes in the server's PHP settings, potentially compromising the application and its data integrity.
