Record summary

CVE-2020-1943 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

Data sent with contentId to /control/stream is not sanitized, allowing XSS attacks in Apache OFBiz 16.11.01 to 16.11.07.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Dec 5, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE List16.11.01 to 16.11.07affected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryMEDIUMApache OFBiz <=16.11.07 - Cross-Site ScriptingCVSS 6.1

Apache OFBiz 16.11.01 to 16.11.07 is vulnerable to cross-site scripting because data sent with contentId to /control/stream is not sanitized.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute malicious scripts in the context of the victim's browser, potentially leading to session hijacking, defacement, or theft of sensitive information.

Remediation

Upgrade Apache OFBiz to a version higher than 16.11.07 to mitigate this vulnerability.

WeaknessesCWE-79
Authorspdteam
Template tagscve2020cveapachexssofbizvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:apache:ofbiz:*:*:*:*:*:*:*:*
Shodan: http.html:"ofbiz"
Shodan: ofbiz.visitor=
FOFA: body="ofbiz"
FOFA: app="apache_ofbiz"

Source: ProjectDiscovery

References

8