CVE-2025-9734 | O2OA up to 10.0-410 Personal Profile Page stat name/alias/description/applicationName cross site scripting (Issue 186 / EUVD-2025-26298)
A vulnerability was found in O2OA up to 10.0-410 and classified as problematic. The impacted element is an unknown function of the file /x_query_assemble_designer/jaxrs/stat of the component Personal Profile Page. The manipulation of the argument name/alias/description/applicationName results in cross site scripting.
This vulnerability is reported as CVE-2025-9734. The attack can be launched remotely. Moreover, an exploit is present.
The vendor replied in the GitHub issue (translated from simplified Chinese): "This issue will be fixed in the new version."