Reflected XSS Vulnerability in O2OA Forum Posting Function
CVE-2026-52370
6.1MEDIUM
What is CVE-2026-52370?
The O2OA application version 10 is susceptible to a reflected cross-site scripting (XSS) vulnerability within its forum posting function. This security flaw allows an attacker to craft a malicious URL which, when accessed by a victim, executes arbitrary JavaScript in the context of their web browser. As a result, sensitive user information may be compromised or unauthorized actions performed on behalf of the victim. It is crucial for users of O2OA to be aware of this vulnerability and take necessary precautions to protect their systems.
