CVE-2025-9680: O2OA Personal Profile page cross site scripting
A vulnerability was detected in O2OA up to 10.0-410. This impacts an unknown function of the file /xportalassembledesigner/jaxrs/page of the component Personal Profile Page. Performing manipulation results in cross site scripting. The attack can be initiated remotely. The exploit is now public and may be used. The vendor replied in the GitHub issue (translated from simplified Chinese): "This issue will be fixed in the new version."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9680?
CVE-2025-9680 is classified as a high severity vulnerability due to its potential for exploitation via cross site scripting.
How do I fix CVE-2025-9680?
To mitigate CVE-2025-9680, update your O2OA software to a version beyond 10.0-410 where the vulnerability is resolved.
What impacts are associated with CVE-2025-9680?
CVE-2025-9680 impacts the Personal Profile Page component of O2OA, allowing for remote cross site scripting attacks.
Who is affected by CVE-2025-9680?
Users of O2OA versions up to and including 10.0-410 are affected by CVE-2025-9680.
Can CVE-2025-9680 be exploited remotely?
Yes, CVE-2025-9680 can be exploited remotely, making it crucial for users to take immediate action.