CVE-2025-9715: O2OA Personal Profile script cross site scripting
A vulnerability was found in O2OA up to 10.0-410. Affected is an unknown function of the file /xcmsassemblecontrol/jaxrs/script of the component Personal Profile Page. The manipulation of the argument name/alias/description results in cross site scripting. The attack can be launched remotely. The exploit has been made public and could be used. The vendor replied in the GitHub issue (translated from simplified Chinese): "This issue will be fixed in the new version."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9715?
CVE-2025-9715 is classified as a high severity vulnerability due to its potential to allow cross site scripting attacks.
How do I fix CVE-2025-9715?
To mitigate CVE-2025-9715, ensure that input validation and output encoding are properly implemented on the Personal Profile Page components.
Which software versions are affected by CVE-2025-9715?
CVE-2025-9715 affects O2OA Personal Profile Page versions up to and including 10.0-410.
What type of attack is associated with CVE-2025-9715?
CVE-2025-9715 is associated with cross site scripting (XSS) attacks that exploit user input fields.
Is there any public exploitation known for CVE-2025-9715?
Currently, there is no widely reported exploitation of CVE-2025-9715, but it poses a significant security risk if left unaddressed.