A weakness has been identified in O2OA up to 10.0-410. This affects an unknown part of the file /x_organization_assemble_control/jaxrs/person/ of the component Personal Profile Page. Executing manipulation of the argument Description can lead to cross site scripting. The attack can be launched remotely. The vendor replied in the GitHub issue (translated from simplified Chinese): "This issue will be fixed in the new version."
History

Tue, 16 Sep 2025 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Zoneland
Zoneland o2oa
CPEs cpe:2.3:a:zoneland:o2oa:*:*:*:*:*:*:*:*
Vendors & Products Zoneland
Zoneland o2oa

Fri, 29 Aug 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 29 Aug 2025 15:15:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in O2OA up to 10.0-410. This affects an unknown part of the file /x_organization_assemble_control/jaxrs/person/ of the component Personal Profile Page. Executing manipulation of the argument Description can lead to cross site scripting. The attack can be launched remotely. The vendor replied in the GitHub issue (translated from simplified Chinese): "This issue will be fixed in the new version."
Title O2OA Personal Profile person cross site scripting
Weaknesses CWE-79
CWE-94
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:P/A:N/E:ND/RL:ND/RC:C'}

cvssV3_0

{'score': 3.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:X/RL:X/RC:C'}

cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:X/RL:X/RC:C'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-08-29T15:02:10.777Z

Updated: 2025-08-29T15:29:57.181Z

Reserved: 2025-08-29T07:03:08.759Z

Link: CVE-2025-9655

cve-icon Vulnrichment

Updated: 2025-08-29T15:29:51.461Z

cve-icon NVD

Status : Analyzed

Published: 2025-08-29T15:15:40.870

Modified: 2025-09-16T16:34:34.900

Link: CVE-2025-9655

cve-icon Redhat

No data.