Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-25370

Опубликовано: 02 сент. 2022
Источник: nvd
CVSS3: 5.4
EPSS Низкий

Описание

Apache OFBiz uses the Birt plugin (https://eclipse.github.io/birt-website/) to create data visualizations and reports. In Apache OFBiz release 18.12.05, and earlier versions, by leveraging a vulnerability in Birt (https://bugs.eclipse.org/bugs/show_bug.cgi?id=538142), an unauthenticated malicious user could perform a stored XSS attack in order to inject a malicious payload and execute it using the stored XSS.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:apache:ofbiz:*:*:*:*:*:*:*:*
Версия до 18.12.06 (исключая)

EPSS

Процентиль: 80%
0.01411
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79
CWE-79

Связанные уязвимости

CVSS3: 5.4
github
больше 3 лет назад

Apache OFBiz uses the Birt plugin (https://eclipse.github.io/birt-website/) to create data visualizations and reports. In Apache OFBiz release 18.12.05, and earlier versions, by leveraging a vulnerability in Birt (https://bugs.eclipse.org/bugs/show_bug.cgi?id=538142), an unauthenticated malicious user could perform a stored XSS attack in order to inject a malicious payload and execute it using the stored XSS.

EPSS

Процентиль: 80%
0.01411
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79
CWE-79