CVE-2025-9736: O2OA Personal Profile statement cross site scripting
A security vulnerability has been detected in O2OA up to 10.0-410. This impacts an unknown function of the file /xqueryassembledesigner/jaxrs/statement of the component Personal Profile Page. Such manipulation of the argument description/queryName leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The vendor replied in the GitHub issue (translated from simplified Chinese): "This issue will be fixed in the new version."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9736?
The severity of CVE-2025-9736 is high due to its ability to enable cross-site scripting attacks.
How do I fix CVE-2025-9736?
To fix CVE-2025-9736, ensure that user input on the Personal Profile Page is properly sanitized.
Who is affected by CVE-2025-9736?
CVE-2025-9736 affects users of O2OA Personal Profile Page up to version 10.0-410.
What components are involved in CVE-2025-9736?
CVE-2025-9736 involves the /x_query_assemble_designer/jaxrs/statement component of the Personal Profile Page.
What type of vulnerability is CVE-2025-9736?
CVE-2025-9736 is a cross-site scripting (XSS) vulnerability.