CVE-2025-9717: O2OA Personal Profile unit cross site scripting
A vulnerability was identified in O2OA up to 10.0-410. Affected by this issue is some unknown functionality of the file /xorganizationassemblecontrol/jaxrs/unit/ of the component Personal Profile Page. Such manipulation of the argument name/shortName/distinguishedName/pinyin/pinyinInitial/levelName leads to cross site scripting. The attack may be launched remotely. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9717?
CVE-2025-9717 has been classified with a severity rating that indicates potential risk to the Personal Profile Page functionality.
How do I fix CVE-2025-9717?
To remediate CVE-2025-9717, it is recommended to upgrade the O2OA Personal Profile Page to version above 10.0-410.
What components are affected by CVE-2025-9717?
CVE-2025-9717 affects the Personal Profile Page component of the O2OA software.
What versions of O2OA are impacted by CVE-2025-9717?
O2OA versions up to and including 10.0-410 are impacted by CVE-2025-9717.
Can CVE-2025-9717 lead to data manipulation?
Yes, CVE-2025-9717 may allow for manipulation of various argument parameters within the affected component.