CVE-2025-9735 | O2OA up to 10.0-410 Personal Profile Page table description/applicationName/queryName cross site scripting (Issue 187)
A vulnerability was found in O2OA up to 10.0-410. It has been classified as problematic. This affects an unknown function of the file /x_query_assemble_designer/jaxrs/table of the component Personal Profile Page. This manipulation of the argument description/applicationName/queryName causes cross site scripting.
This vulnerability appears as CVE-2025-9735. The attack may be initiated remotely. In addition, an exploit is available.
The vendor replied in the GitHub issue (translated from simplified Chinese): "This issue will be fixed in the new version."