Xinhu Rainrock RockOA
cpe:2.3:a:rockoa:xinhu:*:*:*:*:*:*:*
- 2.7.0
A cross-site scripting (XSS) vulnerability has been identified in Xinhu Rainrock RockOA version 2.7.0. The issue arises in the 'urltestAction' function within 'cliAction.php', where the 'm' parameter can be manipulated to inject arbitrary web scripts or HTML. This injected content is then executed in the context of the user's browser.
Exploitation of this vulnerability allows for reflected cross-site scripting, where injected scripts are executed in the victim's browser.
To reproduce this vulnerability, send a GET request to 'task.php' with the 'm' parameter set to 'cli|runt', the 'a' parameter set to 'urltest', and include malicious JavaScript in the 'id' and 'id2' parameters. The injected scripts will be executed in the browser.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.