This is a technical writeup describing a stored XSS vulnerability in Apache OFBiz v16.11.05. It details the steps to reproduce the vulnerability, including the specific field ('Text Data') and section ('ViewForumMessage') where input sanitization is lacking.
Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target:Apache OFBiz v16.11.05
Auth required
Prerequisites:Access to the E-Commerce application · Valid user credentials