Vulnerabilities > Rockoa > High

DATE CVE VULNERABILITY TITLE RISK
2024-07-31 CVE-2024-7327 SQL Injection vulnerability in Rockoa Xinhu 2.6.2
A vulnerability classified as critical was found in Xinhu RockOA 2.6.2.
network
low complexity
rockoa CWE-89
8.8
2023-09-29 CVE-2023-5296 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Rockoa 1.1/15.X3Amdi/2.3.2
A vulnerability was found in Xinhu RockOA 1.1/2.3.2/15.X3amdi and classified as problematic.
network
low complexity
rockoa CWE-640
7.5
2023-09-29 CVE-2023-5297 Files or Directories Accessible to External Parties vulnerability in Rockoa 2.3.2
A vulnerability was found in Xinhu RockOA 2.3.2.
network
low complexity
rockoa CWE-552
7.5
2023-03-19 CVE-2023-1501 Unrestricted Upload of File with Dangerous Type vulnerability in Rockoa 2.3.2
A vulnerability, which was classified as critical, was found in RockOA 2.3.2.
network
low complexity
rockoa CWE-434
8.8
2021-02-05 CVE-2020-18716 SQL Injection vulnerability in Rockoa 1.8.7
SQL Injection in Rockoa v1.8.7 allows remote attackers to gain privileges due to loose filtering of parameters in wordAction.php.
network
low complexity
rockoa CWE-89
7.5
2021-02-05 CVE-2020-18714 SQL Injection vulnerability in Rockoa 1.8.7
SQL Injection in Rockoa v1.8.7 allows remote attackers to gain privileges due to loose filtering of parameters in wordModel.php's getdata function.
network
low complexity
rockoa CWE-89
7.5
2021-02-05 CVE-2020-18713 SQL Injection vulnerability in Rockoa 1.8.7
SQL Injection in Rockoa v1.8.7 allows remote attackers to gain privileges due to loose filtering of parameters in customerAction.php
network
low complexity
rockoa CWE-89
7.5