Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-479x-2w9f-6grr

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The forum implementation in the ecommerce component in the Apache Open For Business Project (OFBiz) trusts the (1) dataResourceTypeId, (2) contentTypeId, and certain other hidden form fields, which allows remote attackers to create unauthorized types of content, modify content, or have other unknown impact.

The forum implementation in the ecommerce component in the Apache Open For Business Project (OFBiz) trusts the (1) dataResourceTypeId, (2) contentTypeId, and certain other hidden form fields, which allows remote attackers to create unauthorized types of content, modify content, or have other unknown impact.

EPSS

Процентиль: 87%
0.03174
Низкий

Связанные уязвимости

nvd
около 19 лет назад

The forum implementation in the ecommerce component in the Apache Open For Business Project (OFBiz) trusts the (1) dataResourceTypeId, (2) contentTypeId, and certain other hidden form fields, which allows remote attackers to create unauthorized types of content, modify content, or have other unknown impact.

EPSS

Процентиль: 87%
0.03174
Низкий