CVE-2025-9719: O2OA Personal Profile script cross site scripting
A weakness has been identified in O2OA up to 10.0-410. This vulnerability affects unknown code of the file /xprocessplatformassembledesigner/jaxrs/script of the component Personal Profile Page. Executing manipulation of the argument name/alias/description/applicationName can lead to cross site scripting. The attack can be executed remotely. The exploit has been made available to the public and could be exploited.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9719?
CVE-2025-9719 is considered a medium severity vulnerability due to its potential for exploitation through manipulation of user input.
How do I fix CVE-2025-9719?
To fix CVE-2025-9719, ensure you upgrade your O2OA software to a version higher than 10.0-410.
What components are affected by CVE-2025-9719?
CVE-2025-9719 affects the Personal Profile Page component of O2OA.
What types of attacks can CVE-2025-9719 facilitate?
CVE-2025-9719 can facilitate attacks through manipulation targeting the input parameters such as name, alias, description, and applicationName.
Is there a workaround for CVE-2025-9719?
Currently, there are no officially reported workarounds for CVE-2025-9719, and upgrading is the recommended solution.