Sceawere

Vulnerability Detail

CVE-2026-108571UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Xinhu Rainrock RockOA SQL Injection

Vulnerability Metadata

Severity
High
Score / CVSS
7.3
Creation Date
4h ago
Vendor
Xinhu
Product
Rainrock RockOA
Attack Type
SQL Injection
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A weakness has been identified in Xinhu Rainrock RockOA up to 2.7.6. This impacts the function kqjcmdModel::returnchuli of the file webmain/task/openapi/openkqjAction.php of the component Openkqj Action. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.3",
  "pubDate": "2026-10-11T11:17:00.197Z",
  "pubdate": "2026-10-11T11:17:00.197Z",
  "executiveSummary": "A critical SQL injection vulnerability has been identified in Xinhu Rainrock RockOA versions up to 2.7.6. The flaw resides within the Openkqj Action component, specifically affecting the kqjcmdModel::returnchuli function.\nThis vulnerability allows an unauthenticated, remote attacker to execute arbitrary SQL commands against the backend database by manipulating the ID argument. Successful exploitation could lead to unauthorized data extraction, modification, or potential administrative compromise of the underlying database management system.\nGiven that the vulnerability is remotely exploitable, has a publicly available exploit, and the vendor has remained unresponsive, the risk to affected deployments is severe. Immediate defensive measures are required to mitigate potential exploitation attempts.",
  "technicalDetails": "The vulnerability is a classic SQL injection flaw located in the file webmain/task/openapi/openkqjAction.php within the kqjcmdModel::returnchuli function. The core issue stems from improper neutralization of user-supplied data passed through the ID argument before it is utilized in database queries.\nIn RockOA, the Openkqj Action component processes incoming requests that are handled by the kqjcmdModel. When the returnchuli function processes input, the ID parameter is concatenated directly into a database query string without adequate sanitization, prepared statements, or parameterization. This lack of input validation enables an attacker to break out of the intended query structure and inject malicious SQL syntax.\nThe attack flow begins with an attacker sending a crafted HTTP request to the vulnerable endpoint associated with the Openkqj Action. The payload within the ID parameter is designed to alter the logic of the SQL statement execution. Because the application processes this input without restriction, the backend database engine interprets the injected malicious SQL commands as part of the legitimate application query.\nThe exploitation allows an attacker to perform unauthorized operations, such as extracting sensitive information from the database (e.g., administrator credentials, system configuration details, or user data), modifying system records, or potentially executing administrative functions depending on the database user permissions associated with the application. The attack is fully remote and does not require prior authentication or elevated privileges, significantly lowering the barrier for exploitation. Given the public availability of exploit code, the window for remediation is constrained, as automated scanners and malicious actors can easily leverage the existing research to conduct widespread reconnaissance or targeted attacks against vulnerable RockOA instances."
}
CVE-2026-108571: Xinhu Rainrock RockOA SQL Injection (HIGH Severity, CVSS: 7.3) | Sceawere