PatchSiren

Xinhu CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Xinhu CVE published 2026-10-11

CVE-2026-108571

A SQL injection vulnerability has been identified in Xinhu Rainrock RockOA up to 2.7.6, specifically in the function kqjcmdModel::returnchuli of the file webmain/task/openapi/openkqjAction.php of the component Openkqj Action. This weakness allows remote attackers to manipulate the argument ID, potentially leading to unauthorized database interactions.