What is CVE-2026-52370?
CVE-2026-52370 is a reflected cross-site scripting (XSS) vulnerability in the Forum posting function of O2OA. This flaw allows attackers to execute arbitrary JavaScript in a victim's browser via a crafted URL. Users should avoid clicking untrusted links, and administrators must apply the latest O2OA security patches.
Azərbaycanca: CVE-2026-52370 O2OA platformasının Forum bölməsində aşkar edilmiş reflected XSS zəifliyidir. Bu zəiflik təcavüzkara xüsusi hazırlanmış URL vasitəsilə qurbanın brauzerində ixtiyari JavaScript kodunu icra etməyə imkan verir. İstifadəçilər şübhəli linklərə klikləməməli, inzibatçılar isə O2OA-nın ən son təhlükəsizlik yeniləmələrini tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which component of the O2OA platform is affected by CVE-2026-52370?
This reflected XSS vulnerability exists in the Forum posting function of the O2OA platform, allowing attackers to execute arbitrary JavaScript in a victim's browser via a crafted URL.
What should be done to protect against CVE-2026-52370?
Users should avoid clicking untrusted links, and administrators must apply the latest O2OA security patches.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.