Cross-Site Scripting Vulnerability in O2OA Personal Profile Page
CVE-2025-9683
Key Information:
Badges
What is CVE-2025-9683?
A cross-site scripting vulnerability was discovered in the Personal Profile Page of O2OA versions up to 10.0-410. This flaw arises from improper handling of user input within the /x_cms_assemble_control/jaxrs/form component, allowing attackers to execute arbitrary scripts in the web application's context. The potential for remote exploitation makes this a significant concern, as malicious users can leverage this vulnerability to affect users visiting the compromised profile page. The vendor has acknowledged the issue and is in the process of releasing a fix in a forthcoming update.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
O2OA 10.0-410
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
