PT-2022-17538 · Apache · Apache Ofbiz

Mal

+1

·

Published

2022-09-02

·

Updated

2022-09-07

·

CVE-2022-25813

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Apache OFBiz versions 18.12.05 and earlier
Description The issue allows an attacker, acting as an anonymous user of the ecommerce plugin, to insert malicious content in the "Subject" field of a message from the "Contact us" page. This can lead to a Server-Side Template Injection (SSTI) when a party manager lists communications in the party component, potentially resulting in Remote Code Execution (RCE).
Recommendations For Apache OFBiz versions 18.12.05 and earlier, consider restricting access to the "Contact us" page or validating and sanitizing user input in the "Subject" field to prevent malicious content insertion. As a temporary workaround, restrict the ability of anonymous users to send messages through the ecommerce plugin until a fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2022-25813

Affected Products

Apache Ofbiz