Cross Site Scripting Vulnerability in Xinhu Rainrock RockOA API
CVE-2026-0588
5.1MEDIUM
What is CVE-2026-0588?
A vulnerability has been identified in Xinhu Rainrock RockOA versions up to 2.7.1, stemming from an unknown functionality in the 'rockfun.php' component of its API. This flaw allows for the manipulation of the argument callback, resulting in cross-site scripting (XSS) that can be exploited remotely. Publicly available exploit techniques expose systems to potential attacks, emphasizing the importance of addressing this issue promptly. Despite being alerted to this matter, the vendor has yet to provide a response regarding a patch or mitigation strategies.
Affected Version(s)
Rainrock RockOA 2.7.0
Rainrock RockOA 2.7.1
