PT-2025-35391 · O2Oa · O2Oa

Colorfullbz

·

Published

2025-08-31

·

Updated

2025-08-31

·

CVE-2025-9717

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions O2OA versions prior to 10.0-410
Description A vulnerability exists in O2OA that allows for cross site scripting. The issue is related to an unknown functionality within the file /x organization assemble control/jaxrs/unit/ of the Personal Profile Page component. Manipulation of the arguments name, shortName, distinguishedName, pinyin, pinyinInitial, and levelName can trigger the vulnerability. The attack can be launched remotely.
Recommendations Update O2OA to version 10.0-410 or later.

Exploit

Fix

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-9717

Affected Products

O2Oa