Junglewise Threat Intelligence

CVE-2026-52370: O2OA reflected XSS in Forum posting

CVE-2026-52370 · Severity: medium · CVSS 6.1 · Published 2026-08-04

Executive brief

O2OA is an open-source enterprise OA (office automation) and collaboration platform used by organizations for workflow management, document handling, and team coordination. A reflected cross-site scripting vulnerability in the Forum posting feature allows attackers to inject malicious JavaScript code via a specially crafted URL, which executes in a victim's browser when clicked. This could lead to session hijacking, credential theft, or defacement of user data within the O2OA system.

Technical details

This is a reflected cross-site scripting (XSS) vulnerability in O2OA v10's Forum posting function. The vulnerability exists because user-supplied input from URL parameters is not properly sanitized or HTML-encoded before being reflected in the response. An attacker can craft a malicious URL containing JavaScript payload that, when visited by an authenticated user, executes arbitrary code in the context of the victim's browser and authenticated session. The attack requires social engineering (convincing a user to click a malicious link) but does not require prior authentication by the attacker. Patch availability for this vulnerability is not specified in the advisory.

Affected products

  • O2OA O2OA v10

Timeline

  • 2026-08-04: disclosed

References

Related threats