PT-2025-35393 · O2Oa · O2Oa

Colorfullbz

·

Published

2025-08-31

·

Updated

2025-08-31

·

CVE-2025-9719

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions O2OA versions up to 10.0-410
Description A weakness has been identified in O2OA that allows for cross site scripting. The issue affects unknown code within the /x processplatform assemble designer/jaxrs/script file of the Personal Profile Page component. Manipulation of the name, alias, description, or applicationName arguments can be exploited remotely. The exploit has been made publicly available.
Recommendations Versions prior to 10.0-410: As a temporary workaround, consider restricting or disabling the use of the Personal Profile Page component until a fix is available.

Exploit

Fix

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-9719

Affected Products

O2Oa