← Back

Zoneland

zoneland

25 CVEs • 1 product

Products (1)

Click to collapse
Toggle
O2oa
o2oa

CVEs (25)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zoneland
1O2oa
Jun 17, 2026
Jan 31, 2025
N/A· v4
6.1 MEDIUM· v3
N/A· v2
O2OA 9.1.3 is vulnerable to Cross Site Scripting (XSS) in Meetings - Settings.
1Zoneland
1O2oa
Jun 17, 2026
May 24, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
An arbitrary file upload vulnerability in O2OA v8.3.8 allows attackers to execute arbitrary code via uploading a crafted PDF file.
1Zoneland
1O2oa
Jun 17, 2026
Apr 12, 2024
N/A· v4
5.9 MEDIUM· v3
2.6 LOW· v2
A vulnerability classified as problematic has been found in Zhejiang Land Zongheng Network Technology O2OA up to 20240403. Affected is an unknown function of the file /x_portal_assemble_surface/jaxrs/portal/list?v=8.2.3-...Show more
A vulnerability classified as problematic has been found in Zhejiang Land Zongheng Network Technology O2OA up to 20240403. Affected is an unknown function of the file /x_portal_assemble_surface/jaxrs/portal/list?v=8.2.3-4-43f4fe3. The manipulation leads to information disclosure. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. VDB-260478 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Zoneland
1O2oa
Jun 17, 2026
Nov 30, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Remote Code Execution (RCE) vulnerability in o2oa version 8.1.2 and before, allows attackers to create a new interface in the service management function to execute JavaScript.
1Zoneland
1O2oa
Jun 17, 2026
Feb 17, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
O2OA v6.4.7 was discovered to contain a remote code execution (RCE) vulnerability via /x_program_center/jaxrs/invoke.