Cross-Site Scripting Vulnerability in Xinhu Rainrock RockOA Software
CVE-2026-0587

5.1MEDIUM

Key Information:

Vendor

Xinhu

Vendor
CVE Published:
5 January 2026

What is CVE-2026-0587?

A security flaw has been identified in the Xinhu Rainrock RockOA software, specifically within the Cover Image Handler functionality found in the file rock_page_gong.php. An attacker can exploit this vulnerability by manipulating the argument 'fengmian', which may result in cross-site scripting (XSS) attacks. This type of attack can be carried out remotely, posing a significant risk to users of affected versions. Despite efforts to inform the vendor of this critical issue, there has been no response regarding remediation.

Affected Version(s)

Rainrock RockOA 2.7.0

Rainrock RockOA 2.7.1

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

BlackSpdier (VulDB User)
.