Impact
The vulnerability is a SQL injection flaw in the getOrder function of Xinhu Rainrock RockOA's webmainAction.php. Manipulation of the highorder parameter allows injection of arbitrary SQL statements, giving an attacker the ability to execute database queries beyond the intended application logic.
Affected Systems
All installations of Xinhu Rainrock RockOA version 2.7.6 and earlier are vulnerable. Any instance that exposes the webmainAction.php component is potentially affected.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is not available, but the vulnerability can be triggered remotely and a public exploit is available, making exploitation feasible. The issue is not in the CISA KEV catalog, yet its remote nature and the potential for database compromise warrant prompt attention.
OpenCVE Enrichment