Junglewise Threat Intelligence

CVE-2026-84153: Xinhu Rainrock RockOA SQL injection in publicsavevalue

CVE-2026-84153 · Severity: medium · CVSS 6.3 · Published 2026-09-01

Executive brief

Xinhu Rainrock RockOA is an office automation platform used for business workflow and document management. A SQL injection vulnerability in the data value update endpoint allows authenticated users to extract or modify sensitive data, including administrator passwords, by injecting malicious SQL code through time-delay techniques.

Technical details

A time-based blind SQL injection vulnerability exists in the `/index.php?m=index&a=publicsavevalue&ajaxbool=true` endpoint of Xinhu Rainrock RockOA version 2.3.2 and earlier. The `value` parameter undergoes minimal input validation (only single-quote escaping and a keyword blacklist) before being passed to the `toaddval()` function. When the value starts with `(&;)`, this prefix is stripped and the remaining content is inserted directly into the SQL UPDATE statement without quote enclosure, bypassing quote-based protections. An authenticated attacker (with only regular user privileges) can inject arbitrary SQL fragments using the `BENCHMARK()` function and SQL comments to create measurable time delays and extract data character-by-character. The vulnerability requires a valid login session but no elevated privileges; patches or workarounds from the vendor have not been confirmed.

Affected products

  • Xinhu Rainrock RockOA up to 2.3.2

Timeline

  • 2026-09-01: disclosed

References