Vulnerabilities > Rockoa > Rockoa > 2.3.2

DATE CVE VULNERABILITY TITLE RISK
2023-12-13 CVE-2023-49363 SQL Injection vulnerability in Rockoa
Rockoa <2.3.3 is vulnerable to SQL Injection.
network
low complexity
rockoa CWE-89
critical
9.8
2023-09-29 CVE-2023-5296 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Rockoa 1.1/15.X3Amdi/2.3.2
A vulnerability was found in Xinhu RockOA 1.1/2.3.2/15.X3amdi and classified as problematic.
network
low complexity
rockoa CWE-640
7.5
2023-09-29 CVE-2023-5297 Files or Directories Accessible to External Parties vulnerability in Rockoa 2.3.2
A vulnerability was found in Xinhu RockOA 2.3.2.
network
low complexity
rockoa CWE-552
7.5
2023-03-31 CVE-2023-1773 Code Injection vulnerability in Rockoa 2.3.2
A vulnerability was found in Rockoa 2.3.2.
network
low complexity
rockoa CWE-94
critical
9.8
2023-03-19 CVE-2023-1501 Unrestricted Upload of File with Dangerous Type vulnerability in Rockoa 2.3.2
A vulnerability, which was classified as critical, was found in RockOA 2.3.2.
network
low complexity
rockoa CWE-434
8.8