CVE-2020-9496
MEDIUM EXPLOITED IN THE WILD NUCLEIApache Ofbiz - Insecure Deserialization
Title source: ruleDescription
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
Exploits (9)
nomisec
SUSPICIOUS
1 stars
by Vulnmachines · remote
https://github.com/Vulnmachines/apache-ofbiz-CVE-2020-9496
Nuclei Templates (1)
Apache OFBiz 17.12.03 - Cross-Site Scripting
MEDIUMby dwisiswant0
Shodan:
http.html:"ofbiz" || ofbiz.visitor=
FOFA:
body="ofbiz" || app="apache_ofbiz"
References (10)
Scores
CVSS v3
6.1
EPSS
0.9377
EPSS Percentile
99.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitation Intel
VulnCheck KEV
2021-09-22
InTheWild.io
2021-09-22
Classification
CWE
CWE-502
CWE-79
Status
published
Affected Products (1)
apache/ofbiz
Timeline
Published
Jul 15, 2020
Tracked Since
Feb 18, 2026