PT-2022-17538 · Apache · Apache Ofbiz
Mal
+1
·
Published
2022-09-02
·
Updated
2022-09-07
·
CVE-2022-25813
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Apache OFBiz versions 18.12.05 and earlier
Description
The issue allows an attacker, acting as an anonymous user of the ecommerce plugin, to insert malicious content in the "Subject" field of a message from the "Contact us" page. This can lead to a Server-Side Template Injection (SSTI) when a party manager lists communications in the party component, potentially resulting in Remote Code Execution (RCE).
Recommendations
For Apache OFBiz versions 18.12.05 and earlier, consider restricting access to the "Contact us" page or validating and sanitizing user input in the "Subject" field to prevent malicious content insertion. As a temporary workaround, restrict the ability of anonymous users to send messages through the ecommerce plugin until a fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Ofbiz