Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-25813
HistorySep 02, 2022 - 7:15 a.m.

Code injection

2022-09-0207:15:00
PRIOn knowledge base
www.prio-n.com
8
apache ofbiz
code injection
versions 18.12.05
ecommerce plugin
anonymous user
malicious content
message subject
contact us page
party manager
communications
ssti
rce

7.4 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

71.5%

In Apache OFBiz, versions 18.12.05 and earlier, an attacker acting as an anonymous user of the ecommerce plugin, can insert a malicious content in a message “Subject” field from the “Contact us” page. Then a party manager needs to list the communications in the party component to activate the SSTI. A RCE is then possible.

CPENameOperatorVersion
ofbizlt18.12.06

7.4 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

71.5%

Related for PRION:CVE-2022-25813