CVE-2014-0232
published 2014-08-22CVE-2014-0232: Multiple cross-site scripting (XSS) vulnerabilities in framework/common/webcommon/includes/messages.ftl in Apache OFBiz 11.04.01 before 11.04.05 and 12.04.01…
PriorityP424medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
8.19%
94.2th percentile
Multiple cross-site scripting (XSS) vulnerabilities in framework/common/webcommon/includes/messages.ftl in Apache OFBiz 11.04.01 before 11.04.05 and 12.04.01 before 12.04.04 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, which are not properly handled in a (1) result or (2) error message.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | ofbiz | — | — |
| apache | ofbiz | — | — |
| apache | ofbiz | — | — |
| apache | ofbiz | — | — |
| apache | ofbiz | — | — |
| apache | ofbiz | — | — |
| apache | ofbiz | — | — |
| apache | ofbiz | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_apache4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r8pv-f253-ph8x: Multiple cross-site scripting (XSS) vulnerabilities in framework/common/webcommon/includes/messages
ghsa_unreviewed·2022-05-14
CVE-2014-0232 [MEDIUM] CWE-79 GHSA-r8pv-f253-ph8x: Multiple cross-site scripting (XSS) vulnerabilities in framework/common/webcommon/includes/messages
Multiple cross-site scripting (XSS) vulnerabilities in framework/common/webcommon/includes/messages.ftl in Apache OFBiz 11.04.01 before 11.04.05 and 12.04.01 before 12.04.04 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, which are not properly handled in a (1) result or (2) error message.
Apache
Apache ofbiz: CVE-2014-0232
vendor_apache·CVSS 4.3
CVE-2014-0232 [MEDIUM] Apache ofbiz: CVE-2014-0232
Apache ofbiz: CVE-2014-0232
; affected releases: 12.04.03 and earlier versions (12.04.*), 11.04.04 and earlier versions (11.04.*); fixed in 12.04.04 and 11.04.05
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://ofbiz.apache.org/download.html#vulnerabilitieshttp://packetstormsecurity.com/files/127929/Apache-OFBiz-11.04.04-12.04.03-Cross-Site-Scripting.htmlhttp://seclists.org/oss-sec/2014/q3/405http://secunia.com/advisories/60807http://svn.apache.org/viewvc?view=revision&revision=r1608698http://www.securityfocus.com/archive/1/533163/100/0/threadedhttp://www.securityfocus.com/bid/69286http://www.securitytracker.com/id/1030739https://exchange.xforce.ibmcloud.com/vulnerabilities/95356http://ofbiz.apache.org/download.html#vulnerabilitieshttp://packetstormsecurity.com/files/127929/Apache-OFBiz-11.04.04-12.04.03-Cross-Site-Scripting.htmlhttp://seclists.org/oss-sec/2014/q3/405http://secunia.com/advisories/60807http://svn.apache.org/viewvc?view=revision&revision=r1608698http://www.securityfocus.com/archive/1/533163/100/0/threadedhttp://www.securityfocus.com/bid/69286http://www.securitytracker.com/id/1030739https://exchange.xforce.ibmcloud.com/vulnerabilities/95356
2014-08-22
Published