Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-25813


In Apache OFBiz, versions 18.12.05 and earlier, an attacker acting as an anonymous user of the ecommerce plugin, can insert a malicious content in a message “Subject” field from the "Contact us" page. Then a party manager needs to list the communications in the party component to activate the SSTI. A RCE is then possible.


Published

2022-09-02T07:15:07.510

Last Modified

2024-11-21T06:53:02.977

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-1336
  • Type: Primary
    CWE-94

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application apache ofbiz < 18.12.06 Yes

References