CVE-2025-9737 | O2OA up to 10.0-410 Personal Profile Page importmodel description/applicationName/queryName cross site scripting (Issue 189)
A vulnerability was found in O2OA up to 10.0-410. It has been rated as problematic. Affected is an unknown function of the file /x_query_assemble_designer/jaxrs/importmodel of the component Personal Profile Page. Performing manipulation of the argument description/applicationName/queryName results in cross site scripting.
This vulnerability is known as CVE-2025-9737. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
The vendor replied in the GitHub issue (translated from simplified Chinese): "This issue will be fixed in the new version."