Filtered by vendor Zoneland Subscriptions
Total 3 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2024-35591 1 Zoneland 1 O2oa 2025-02-13 5.4 Medium
An arbitrary file upload vulnerability in O2OA v8.3.8 allows attackers to execute arbitrary code via uploading a crafted PDF file.
CVE-2023-47418 1 Zoneland 1 O2oa 2024-11-21 9.8 Critical
Remote Code Execution (RCE) vulnerability in o2oa version 8.1.2 and before, allows attackers to create a new interface in the service management function to execute JavaScript.
CVE-2022-22916 1 Zoneland 1 O2oa 2024-11-21 9.8 Critical
O2OA v6.4.7 was discovered to contain a remote code execution (RCE) vulnerability via /x_program_center/jaxrs/invoke.