Lucene search

K
cvelistApacheCVELIST:CVE-2022-25813
HistorySep 02, 2022 - 7:10 a.m.

CVE-2022-25813 Server-Side Template Injection affecting the ecommerce plugin of Apache OFBiz

2022-09-0207:10:18
CWE-1336
apache
www.cve.org
1
cve-2022-25813 apache ofbiz ssti} .

0.003 Low

EPSS

Percentile

71.5%

In Apache OFBiz, versions 18.12.05 and earlier, an attacker acting as an anonymous user of the ecommerce plugin, can insert a malicious content in a message “Subject” field from the “Contact us” page. Then a party manager needs to list the communications in the party component to activate the SSTI. A RCE is then possible.

CNA Affected

[
  {
    "product": "Apache OFBiz",
    "vendor": "Apache Software Foundation",
    "versions": [
      {
        "lessThanOrEqual": "18.12.05",
        "status": "affected",
        "version": "Apache OFBiz",
        "versionType": "custom"
      }
    ]
  }
]

0.003 Low

EPSS

Percentile

71.5%

Related for CVELIST:CVE-2022-25813