SQL Injection Vulnerability in Xinhu Rainrock RockOA Affected by Remote Exploits
CVE-2026-108571
6.9MEDIUM
What is CVE-2026-108571?
A vulnerability has been identified in the Xinhu Rainrock RockOA product up to version 2.7.6. The issue resides in the kqjcmdModel::returnchuli function located in the file webmain/task/openapi/openkqjAction.php. Through manipulation of the argument ID, an attacker can perform a SQL injection which allows unauthorized access and manipulation of the database. This security flaw can be exploited remotely, posing a significant risk to users. Publicly available exploit code increases the urgency for users to apply necessary mitigations. Despite the severity of the disclosure, the vendor has not responded to initial communications regarding this vulnerability.
Affected Version(s)
Rainrock RockOA 2.7.0
Rainrock RockOA 2.7.1
Rainrock RockOA 2.7.2
