CVE-2025-63738

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
09/12/2025
Last modified:
12/12/2025

Description

An issue was discovered in file index.php in Xinhu Rainrock RockOA 2.7.0 allowing attackers to gain sensitive information via phpinfo via the a parameter to the index.php.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:rockoa:rockoa:2.7.0:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools