CVE-2025-9655 Overview
CVE-2025-9655 is a stored cross-site scripting (XSS) vulnerability affecting O2OA collaborative office platform versions up to 10.0-410. The flaw resides in the Personal Profile Page component, specifically the /x_organization_assemble_control/jaxrs/person/ endpoint. Attackers can inject malicious script content through the Description argument, which executes in the context of users viewing the affected profile. The attack is remotely exploitable and requires low privileges plus user interaction. The vendor acknowledged the issue in GitHub issue #172 and indicated that a fix would be included in a future release. The vulnerability is classified under [CWE-79] Improper Neutralization of Input During Web Page Generation.
Critical Impact
Authenticated attackers can persist JavaScript payloads in the Personal Profile Description field, enabling session hijacking, credential theft, and unauthorized actions performed in the context of victim users.
Affected Products
- Zoneland O2OA versions up to and including 10.0-410
- O2OA Personal Profile Page component
- The /x_organization_assemble_control/jaxrs/person/ REST endpoint
Discovery Timeline
- 2025-08-29 - CVE-2025-9655 published to the National Vulnerability Database
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-9655
Vulnerability Analysis
The vulnerability exists in the O2OA person management REST service under /x_organization_assemble_control/jaxrs/person/. The Description field of the Personal Profile Page accepts user-controlled input without sufficient neutralization of HTML or JavaScript content. When another user views the affected profile, the stored payload renders and executes in their browser. This behavior is consistent with a stored (persistent) XSS pattern classified as [CWE-79]. Exploitation requires an authenticated account with permission to edit a personal profile. Victim interaction is required, since the payload triggers when a user loads the profile view. The scope is limited to the O2OA web application, but successful exploitation permits arbitrary script execution under the victim's session.
Root Cause
The root cause is insufficient output encoding and input sanitization on the Description attribute of the person object. The application stores user-supplied content and later renders it in the profile view without escaping HTML control characters. This allows a <script> tag or event-handler attribute to persist and execute.
Attack Vector
An authenticated attacker submits a modified profile update to the vulnerable JAX-RS endpoint. The malicious payload is stored in the person record's Description field. When a colleague, administrator, or any user with access views the profile, the browser interprets the injected content as executable script.
No verified exploit code is publicly available. Refer to the GitHub Issue #172 for reproduction details reported to the vendor.
Detection Methods for CVE-2025-9655
Indicators of Compromise
- Profile records containing HTML tags such as <script>, <img onerror=...>, or <svg onload=...> inside the Description field.
- Outbound HTTP requests from user browsers to attacker-controlled domains shortly after loading a profile page.
- Anomalous PUT or POST requests to /x_organization_assemble_control/jaxrs/person/ containing encoded script fragments.
- Session token exfiltration patterns following profile views.
Detection Strategies
- Inspect stored Description fields in the O2OA person database for HTML or JavaScript syntax using regular-expression queries.
- Deploy a Web Application Firewall (WAF) rule that alerts on script-like payloads submitted to the /jaxrs/person/ endpoint.
- Enable Content Security Policy (CSP) reporting to capture inline script violations originating from profile pages.
- Correlate authenticated profile-edit events with subsequent anomalous browser activity from profile viewers.
Monitoring Recommendations
- Log and retain all requests to O2OA REST endpoints under /x_organization_assemble_control/ for retrospective hunting.
- Monitor client-side JavaScript errors and CSP violation reports from the O2OA web front end.
- Alert on newly created or modified user profiles that contain angle brackets, javascript: URIs, or base64-encoded payloads.
How to Mitigate CVE-2025-9655
Immediate Actions Required
- Upgrade O2OA to the version that contains the vendor fix once released, as announced in GitHub Issue #172 Comment.
- Audit existing user profiles and sanitize or clear any Description fields containing HTML or script content.
- Restrict profile-edit permissions to trusted accounts until a patched version is deployed.
- Deploy a Content Security Policy that blocks inline script execution on O2OA pages.
Patch Information
The vendor stated in GitHub Issue #172 that the issue will be fixed in an upcoming release of O2OA. At the time of NVD publication, no specific patched version identifier was released. Administrators should monitor the O2OA GitHub repository for updated builds beyond version 10.0-410.
Workarounds
- Enforce a strict Content Security Policy header such as default-src 'self'; script-src 'self' to block injected inline scripts.
- Configure a reverse proxy or WAF to reject requests to /x_organization_assemble_control/jaxrs/person/ containing angle brackets or javascript: schemes in the Description parameter.
- Apply server-side output encoding at the rendering layer for all person-profile fields.
- Limit the set of users authorized to modify personal profile descriptions until an official patch is applied.
# Example nginx rule to block script-like payloads on the vulnerable endpoint
location /x_organization_assemble_control/jaxrs/person/ {
if ($request_body ~* "(<script|onerror=|onload=|javascript:)") {
return 403;
}
proxy_pass http://o2oa_backend;
}
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
