CVE-2025-22994
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Summary
CVE-2025-22994 is a newly disclosed Cross-Site Scripting (XSS) vulnerability affecting version 9.1.3 of O2OA's Meetings - Settings feature. Maliciously crafted scripts can be injected into the affected webpage, allowing attackers to steal sensitive user data or execute malicious code in the context of the targeted user. Successful exploitation could lead to unauthorized access, session hijacking, or data exfiltration. Users are urged to update their software or implement appropriate security measures, such as Content Security Policy (CSP) and input validation, to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.