Cross-Site Scripting Vulnerability in Xinhu Rainrock RockOA Software
CVE-2026-0587
5.1MEDIUM
What is CVE-2026-0587?
A security flaw has been identified in the Xinhu Rainrock RockOA software, specifically within the Cover Image Handler functionality found in the file rock_page_gong.php. An attacker can exploit this vulnerability by manipulating the argument 'fengmian', which may result in cross-site scripting (XSS) attacks. This type of attack can be carried out remotely, posing a significant risk to users of affected versions. Despite efforts to inform the vendor of this critical issue, there has been no response regarding remediation.
Affected Version(s)
Rainrock RockOA 2.7.0
Rainrock RockOA 2.7.1
