CVE-2025-63738: Rockoa

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

An issue was discovered in file index.php in Xinhu Rainrock RockOA 2.7.0 allowing attackers to gain sensitive information via phpinfo via the a parameter to the index.php.

Affected products

  • Rockoa Rockoa: version 2.7.0 only

Published 2025-12-09. Last modified 2026-06-17.