CVE-2022-25813
In Apache OFBiz, versions 18.12.05 and earlier, an attacker acting as an anonymous user of the ecommerce plugin, can insert a malicious content in a message “Subject” field from the "Contact us" page.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 67.3%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
In Apache OFBiz, versions 18.12.05 and earlier, an attacker acting as an anonymous user of the ecommerce plugin, can insert a malicious content in a message “Subject” field from the "Contact us" page. Then a party manager needs to list the communications in the party component to activate the SSTI. A RCE is then possible.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 67.26% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-1336, CWE-94
- Affected
- apache/ofbiz
- Source
- security@apache.org
References
- http://www.openwall.com/lists/oss-security/2022/09/02/4Mailing List, Patch, Third Party Advisory
- https://lists.apache.org/thread/vmj5s0qb59t0lvzf3vol3z1sc3sgyb2bMailing List, Patch, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2022/09/02/4Mailing List, Patch, Third Party Advisory
- https://lists.apache.org/thread/vmj5s0qb59t0lvzf3vol3z1sc3sgyb2bMailing List, Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.