MEDIUM
Xinhu
CVE published 2026-10-11
CVE-2026-108571
A SQL injection vulnerability has been identified in Xinhu Rainrock RockOA up to 2.7.6, specifically in the function kqjcmdModel::returnchuli of the file webmain/task/openapi/openkqjAction.php of the component Openkqj Action. This weakness allows remote attackers to manipulate the argument ID, potentially leading to unauthorized database interactions.