Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-26211 | A vulnerability was found in Xinhu RockOA up to 2.6.9. Impacted is the function publicsaveAjax of the file /index.php. Performing manipulation results in improper authorization. The attack is possible to be carried out remotely. The exploit has been made public and could be used. |
Thu, 11 Sep 2025 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rockoa
Rockoa rockoa |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:rockoa:rockoa:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Rockoa
Rockoa rockoa |
Sun, 31 Aug 2025 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Xinhu
Xinhu rockoa |
|
| Vendors & Products |
Xinhu
Xinhu rockoa |
Fri, 29 Aug 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 29 Aug 2025 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was found in Xinhu RockOA up to 2.6.9. Impacted is the function publicsaveAjax of the file /index.php. Performing manipulation results in improper authorization. The attack is possible to be carried out remotely. The exploit has been made public and could be used. | |
| Title | Xinhu RockOA index.php publicsaveAjax improper authorization | |
| Weaknesses | CWE-266 CWE-285 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-08-29T14:30:15.523Z
Reserved: 2025-08-28T15:02:48.735Z
Link: CVE-2025-9602
Updated: 2025-08-29T14:30:06.306Z
Status : Analyzed
Published: 2025-08-29T02:15:32.297
Modified: 2026-04-29T01:00:01.613
Link: CVE-2025-9602
No data.
OpenCVE Enrichment
Updated: 2025-08-31T08:41:40Z
EUVD