CVE-2026-84109 | Xinhu Rainrock RockOA up to 2.7.6 webmainAction.php getOrder highorder sql injection
A vulnerability categorized as critical has been discovered in Xinhu Rainrock RockOA up to 2.7.6. Affected by this issue is the function getOrder of the file webmain/webmainAction.php. Executing a manipulation of the argument highorder can lead to sql injection.
This vulnerability is tracked as CVE-2026-84109. The attack can be launched remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More