CVE-2025-9655: O2OA Personal Profile person cross site scripting
A weakness has been identified in O2OA up to 10.0-410. This affects an unknown part of the file /xorganizationassemblecontrol/jaxrs/person/ of the component Personal Profile Page. Executing manipulation of the argument Description can lead to cross site scripting. The attack can be launched remotely. The vendor replied in the GitHub issue (translated from simplified Chinese): "This issue will be fixed in the new version."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9655?
CVE-2025-9655 is a high severity vulnerability due to the risk of cross-site scripting exploitation.
How do I fix CVE-2025-9655?
To fix CVE-2025-9655, validate and sanitize user inputs on the Personal Profile Page to prevent script injection.
What is the impact of CVE-2025-9655?
The impact of CVE-2025-9655 includes potential unauthorized access to user data and session hijacking through script execution.
Which software versions are affected by CVE-2025-9655?
CVE-2025-9655 affects O2OA Personal Profile Page versions up to 10.0-410.
Where can I find more information about CVE-2025-9655?
More information about CVE-2025-9655 can typically be found in security bulletins or vulnerability databases.