O2OA
cpe:2.3:a:zoneland:o2oa:*:*:*:*:*:*:*
- 9.1.3
A cross-site scripting (XSS) vulnerability has been identified in O2OA version 9.1.3, specifically within the Meetings - Settings section. This vulnerability allows attackers to inject payloads that execute arbitrary web scripts and HTML, exploiting a storage-based XSS flaw.
Exploitation of this vulnerability allows for storage-based cross-site scripting, where injected scripts are executed in the context of the user.
To reproduce this vulnerability, log into O2OA version 9.1.3 and navigate to the Meetings - Settings section. Inject a payload into the settings and save it. After refreshing the page, the injected script will execute when the Settings button is clicked again.
A small version fix is planned for release.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.