Executive brief
Xinhu Rainrock RockOA is an office automation platform used for business workflow and document management. A SQL injection vulnerability in the data value update endpoint allows authenticated users to extract or modify sensitive data, including administrator passwords, by injecting malicious SQL code through time-delay techniques.
Technical details
A time-based blind SQL injection vulnerability exists in the `/index.php?m=index&a=publicsavevalue&ajaxbool=true` endpoint of Xinhu Rainrock RockOA version 2.3.2 and earlier. The `value` parameter undergoes minimal input validation (only single-quote escaping and a keyword blacklist) before being passed to the `toaddval()` function. When the value starts with `(&;)`, this prefix is stripped and the remaining content is inserted directly into the SQL UPDATE statement without quote enclosure, bypassing quote-based protections. An authenticated attacker (with only regular user privileges) can inject arbitrary SQL fragments using the `BENCHMARK()` function and SQL comments to create measurable time delays and extract data character-by-character. The vulnerability requires a valid login session but no elevated privileges; patches or workarounds from the vendor have not been confirmed.
Affected products
- Xinhu Rainrock RockOA up to 2.3.2
Timeline
- 2026-09-01: disclosed