A vulnerability was found in O2OA 10. It has been declared as problematic. The impacted element is an unknown function of the component Forum Posting. The manipulation results in cross site scripting.

This vulnerability is identified as CVE-2026-52370. The attack can be executed remotely. There is not any exploit available.