PT-2020-15180 · Apache · Apache Ofbiz

Published

2020-04-01

·

Updated

2023-01-27

·

CVE-2020-1943

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Apache OFBiz versions 16.11.01 through 16.11.07
Description The issue allows for XSS attacks due to unsanitized data sent with the contentId to the "/control/stream" API endpoint.
Recommendations For Apache OFBiz versions 16.11.01 through 16.11.07, as a temporary workaround, consider restricting access to the "/control/stream" API endpoint until a patch is available. Avoid using the contentId parameter in this endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2020-1943

Affected Products

Apache Ofbiz