<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:xinhu:rockoa:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3axinhurockoa/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sun, 11 Oct 2026 12:00:19 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3axinhurockoa/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>SQL Injection Vulnerability in Xinhu Rainrock RockOA</title><link>https://feed.craftedsignal.io/briefs/2026-10-rockoa-sql-injection/</link><pubDate>Sun, 11 Oct 2026 12:00:19 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-rockoa-sql-injection/</guid><description>A SQL injection vulnerability (CVE-2026-108571) in Xinhu Rainrock RockOA versions 2.7.6 and earlier allows remote attackers to execute arbitrary database queries via the ID argument.</description><content:encoded><![CDATA[<p>A SQL injection vulnerability exists in Xinhu Rainrock RockOA versions 2.7.6 and earlier, specifically within the kqjcmdModel::returnchuli function of the openkqjAction.php file. The vulnerability is located in the Openkqj Action component and is triggered by improper sanitization of the ID argument during web requests. Remote attackers can leverage this flaw to manipulate database queries, potentially leading to unauthorized data exfiltration or modification. The vulnerability has been publicly disclosed, and proof-of-concept exploit code is currently circulating. The vendor, Xinhu, was notified prior to public disclosure but failed to respond, and no official patch is currently available. Organizations utilizing RockOA in internet-facing environments are at high risk of exploitation by automated scanners and opportunistic attackers.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated remote attackers to perform unauthorized database operations. This can lead to full compromise of the application data stored within the backend database, potentially including administrative credentials, user information, or sensitive organizational records. Given the public availability of exploit code, the risk of automated mass exploitation is high.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the identification of all internet-facing Xinhu Rainrock RockOA instances within the environment. Since no patch is available, implement restrictive access controls at the web application firewall (WAF) or network perimeter to block requests targeting the openkqjAction.php endpoint. Monitor web server logs for suspicious patterns in the ID parameter, particularly the inclusion of SQL syntax characters such as single quotes, semicolons, or common SQL injection keywords like UNION, SELECT, or SLEEP.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-application</category><category>sql-injection</category><category>cve-2026-108571</category></item></channel></rss>