O2OA Personal Profile table cross site scripting
Published Aug 31, 2025
5.1
MEDIUMCVSS 4.0
EPSS 0.27%
Description
A weakness has been identified in O2OA up to 10.0-410. This affects an unknown function of the file /x_query_assemble_designer/jaxrs/table of the component Personal Profile Page. This manipulation of the argument description/applicationName/queryName causes cross site scripting. The attack may be initiated remotely. The exploit has been made available to the public and could be exploited. The vendor replied in the GitHub issue (translated from simplified Chinese): "This issue will be fixed in the new version."
Affected products
- Vendor n/a Product O2OA Defaultunknown
Affected
- 10.0-410
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| n/a | O2OA | unknown | Affected
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (7)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-26301 Advisory
- https://github.com/o2oa/o2oa/issues/187 exploitissue-trackingIssue TrackingThird Party Advisory
- https://github.com/o2oa/o2oa/issues/187#issue-3332984961 exploitissue-trackingIssue TrackingThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-9735
- https://vuldb.com/?ctiid.322034 signaturepermissions-requiredPermissions RequiredVDB Entry
- https://vuldb.com/?id.322034 vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry
- https://vuldb.com/?submit.637249 third-party-advisoryThird Party AdvisoryVDB Entry
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-26301 | Advisory | |
| https://github.com/o2oa/o2oa/issues/187 | exploitissue-trackingIssue TrackingThird Party Advisory | |
| https://github.com/o2oa/o2oa/issues/187#issue-3332984961 | exploitissue-trackingIssue TrackingThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2025-9735 | ||
| https://vuldb.com/?ctiid.322034 | signaturepermissions-requiredPermissions RequiredVDB Entry | |
| https://vuldb.com/?id.322034 | vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry | |
| https://vuldb.com/?submit.637249 | third-party-advisoryThird Party AdvisoryVDB Entry |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data