CVE-2025-9683 describes a cross-site scripting (XSS) vulnerability in O2OA versions up to 10.0-410, specifically within the Personal Profile Page's /x_cms_assemble_control/jaxrs/form component. This medium-severity vulnerability (CVSS 5.4) can be exploited remotely with low attack complexity, requiring user interaction and low privileges. A successful attack could lead to limited confidentiality and integrity impacts. The exploit for this vulnerability has been publicly disclosed, and the vendor has acknowledged the issue, stating a fix will be included in a new version. Despite public exploit availability, there is currently no evidence of active exploitation, nor is it listed in CISA's KEV catalog. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 10.0-410CPE matchmatch criteria | cpe:2.3:a:zoneland:o2oa:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.