Cross-Site Scripting Vulnerability in O2OA Personal Profile Page
CVE-2025-9683
Key Information:
Badges
What is CVE-2025-9683?
A cross-site scripting vulnerability was discovered in the Personal Profile Page of O2OA versions up to 10.0-410. This flaw arises from improper handling of user input within the /x_cms_assemble_control/jaxrs/form component, allowing attackers to execute arbitrary scripts in the web application's context. The potential for remote exploitation makes this a significant concern, as malicious users can leverage this vulnerability to affect users visiting the compromised profile page. The vendor has acknowledged the issue and is in the process of releasing a fix in a forthcoming update.
Affected Version(s)
O2OA 10.0-410
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved