CVE-2025-22994

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Jan 31, 2025
Updated: Feb 3, 2025
CWE ID 79

Summary

CVE-2025-22994 is a newly disclosed Cross-Site Scripting (XSS) vulnerability affecting version 9.1.3 of O2OA's Meetings - Settings feature. Maliciously crafted scripts can be injected into the affected webpage, allowing attackers to steal sensitive user data or execute malicious code in the context of the targeted user. Successful exploitation could lead to unauthorized access, session hijacking, or data exfiltration. Users are urged to update their software or implement appropriate security measures, such as Content Security Policy (CSP) and input validation, to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share