CVE-2025-9683: O2OA Personal Profile form cross site scripting
A vulnerability was found in O2OA up to 10.0-410. Affected by this issue is some unknown functionality of the file /xcmsassemblecontrol/jaxrs/form of the component Personal Profile Page. The manipulation results in cross site scripting. The attack may be launched remotely. The exploit has been made public and could be used. The vendor replied in the GitHub issue (translated from simplified Chinese): "This issue will be fixed in the new version."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9683?
CVE-2025-9683 has been classified as a medium severity vulnerability due to its potential for cross-site scripting exploits.
How do I fix CVE-2025-9683?
To fix CVE-2025-9683, update O2OA to the latest version that addresses this vulnerability.
What component is affected by CVE-2025-9683?
CVE-2025-9683 affects the Personal Profile Page functionality found in O2OA versions up to 10.0-410.
Can CVE-2025-9683 be exploited remotely?
Yes, CVE-2025-9683 can be exploited remotely, allowing attackers to manipulate the affected file.
What type of vulnerability is CVE-2025-9683?
CVE-2025-9683 is a cross-site scripting (XSS) vulnerability.