Xinhu Rainrock RockOA Cross-Site Scripting Vulnerability

Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in Xinhu Rainrock RockOA version 2.7.0. The issue arises in the 'urltestAction' function within 'cliAction.php', where the 'm' parameter can be manipulated to inject arbitrary web scripts or HTML. This injected content is then executed in the context of the user's browser.

Impact

Exploitation of this vulnerability allows for reflected cross-site scripting, where injected scripts are executed in the victim's browser.

Reproduction

To reproduce this vulnerability, send a GET request to 'task.php' with the 'm' parameter set to 'cli|runt', the 'a' parameter set to 'urltest', and include malicious JavaScript in the 'id' and 'id2' parameters. The injected scripts will be executed in the browser.

Added: Dec 9, 2025, 5:20 PM
Updated: Dec 9, 2025, 11:12 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
5.8
remediation
0.0
relevance
1.4
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.