A vulnerability was found in Campcodes Online Learning Management System 1.0. It has been declared as critical. This issue affects some unknown processing of the file /student_signup.php. The manipulation of the argument Username results in sql injection.
This vulnerability is reported as CVE-2025-9763. The attack can be launched remotely. Moreover, an exploit is present.
A vulnerability was found in Tenda AC9 15.03.05.19. It has been rated as problematic. The impacted element is an unknown function of the file /etc_ro/shadow of the component Administrative Interface. This manipulation causes hard-coded credentials.
This vulnerability is handled as CVE-2025-9731. It is possible to launch the attack on the local host. Additionally, an exploit exists.
A vulnerability was found in O2OA up to 10.0-410 and classified as problematic. The impacted element is an unknown function of the file /x_query_assemble_designer/jaxrs/stat of the component Personal Profile Page. The manipulation of the argument name/alias/description/applicationName results in cross site scripting.
This vulnerability is reported as CVE-2025-9734. The attack can be launched remotely. Moreover, an exploit is present.
The vendor replied in the GitHub issue (translated from simplified Chinese): "This issue will be fixed in the new version."
A vulnerability was found in O2OA up to 10.0-410. It has been classified as problematic. This affects an unknown function of the file /x_query_assemble_designer/jaxrs/table of the component Personal Profile Page. This manipulation of the argument description/applicationName/queryName causes cross site scripting.
This vulnerability appears as CVE-2025-9735. The attack may be initiated remotely. In addition, an exploit is available.
The vendor replied in the GitHub issue (translated from simplified Chinese): "This issue will be fixed in the new version."
A vulnerability was found in O2OA up to 10.0-410. It has been declared as problematic. This impacts an unknown function of the file /x_query_assemble_designer/jaxrs/statement of the component Personal Profile Page. Such manipulation of the argument description/queryName leads to cross site scripting.
This vulnerability is traded as CVE-2025-9736. The attack may be launched remotely. Furthermore, there is an exploit available.
The vendor replied in the GitHub issue (translated from simplified Chinese): "This issue will be fixed in the new version."