CVE-2012-1621
published 2014-06-19CVE-2012-1621: Multiple cross-site scripting (XSS) vulnerabilities in Apache Open For Business Project (aka OFBiz) 10.04.x before 10.04.02 allow remote attackers to inject…
PriorityP423medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
9.79%
95.0th percentile
Multiple cross-site scripting (XSS) vulnerabilities in Apache Open For Business Project (aka OFBiz) 10.04.x before 10.04.02 allow remote attackers to inject arbitrary web script or HTML via (1) a parameter array in freemarker templates, the (2) contentId or (3) mapKey parameter in a cms event request, which are not properly handled in an error message, or unspecified input in (4) an ajax request to the getServerError function in checkoutProcess.js or (5) a Webslinger component request. NOTE: some of these details are obtained from third party information.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | ofbiz | — | — |
| apache | ofbiz | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_apache4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3xpr-w4v3-68p8: Multiple cross-site scripting (XSS) vulnerabilities in Apache Open For Business Project (aka OFBiz) 10
ghsa_unreviewed·2022-05-14
CVE-2012-1621 [MEDIUM] CWE-79 GHSA-3xpr-w4v3-68p8: Multiple cross-site scripting (XSS) vulnerabilities in Apache Open For Business Project (aka OFBiz) 10
Multiple cross-site scripting (XSS) vulnerabilities in Apache Open For Business Project (aka OFBiz) 10.04.x before 10.04.02 allow remote attackers to inject arbitrary web script or HTML via (1) a parameter array in freemarker templates, the (2) contentId or (3) mapKey parameter in a cms event request, which are not properly handled in an error message, or unspecified input in (4) an ajax request to the getServerError function in checkoutProcess.js or (5) a Webslinger component request. NOTE: some of these details are obtained from third party information.
Apache
Apache ofbiz: CVE-2012-1621
vendor_apache·CVSS 4.3
CVE-2012-1621 [MEDIUM] Apache ofbiz: CVE-2012-1621
Apache ofbiz: CVE-2012-1621
; affected releases: 10.04 (10.04.01); fixed in 10.04.02
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://mail-archives.apache.org/mod_mbox/ofbiz-dev/201204.mbox/%3CA126EDA0-06A5-4B67-8CDD-FC5F5AABA147%40apache.org%3Ehttp://mail-archives.apache.org/mod_mbox/www-announce/201204.mbox/%3C2B984C00-EC65-4455-98D3-55735ABE8AF9%40apache.org%3Ehttp://ofbiz.apache.org/download.html#vulnerabilitieshttp://osvdb.org/show/osvdb/81346http://osvdb.org/show/osvdb/81347http://osvdb.org/show/osvdb/81348http://osvdb.org/show/osvdb/81349http://seclists.org/bugtraq/2012/Apr/101http://seclists.org/fulldisclosure/2012/Apr/172http://secunia.com/advisories/48800http://www.securityfocus.com/bid/53023http://www.securitytracker.com/id?1026927https://exchange.xforce.ibmcloud.com/vulnerabilities/74870http://mail-archives.apache.org/mod_mbox/ofbiz-dev/201204.mbox/%3CA126EDA0-06A5-4B67-8CDD-FC5F5AABA147%40apache.org%3Ehttp://mail-archives.apache.org/mod_mbox/www-announce/201204.mbox/%3C2B984C00-EC65-4455-98D3-55735ABE8AF9%40apache.org%3Ehttp://ofbiz.apache.org/download.html#vulnerabilitieshttp://osvdb.org/show/osvdb/81346http://osvdb.org/show/osvdb/81347http://osvdb.org/show/osvdb/81348http://osvdb.org/show/osvdb/81349http://seclists.org/bugtraq/2012/Apr/101http://seclists.org/fulldisclosure/2012/Apr/172http://secunia.com/advisories/48800http://www.securityfocus.com/bid/53023http://www.securitytracker.com/id?1026927https://exchange.xforce.ibmcloud.com/vulnerabilities/74870
2014-06-19
Published