CVE-2025-9646: O2OA calendarConfig cross site scripting
A security flaw has been discovered in O2OA up to 10.0-410. This vulnerability affects unknown code of the file /xorganizationassemblepersonal/jaxrs/definition/calendarConfig. The manipulation of the argument toMonthViewName results in cross site scripting. The attack can be launched remotely. The exploit has been released to the public and may be exploited. The vendor replied in the GitHub issue (translated from simplified Chinese): "This issue will be fixed in the new version."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9646?
CVE-2025-9646 is classified as a cross-site scripting (XSS) vulnerability.
How do I fix CVE-2025-9646?
To fix CVE-2025-9646, update O2OA to a version beyond 10.0-410 that addresses the XSS vulnerability.
What component is affected by CVE-2025-9646?
CVE-2025-9646 affects the /x_organization_assemble_personal/jaxrs/definition/calendarConfig file of O2OA.
What types of attacks can CVE-2025-9646 facilitate?
CVE-2025-9646 can facilitate cross-site scripting attacks that may compromise user data or session integrity.
Which versions of O2OA are impacted by CVE-2025-9646?
CVE-2025-9646 impacts all versions of O2OA up to and including 10.0-410.