CVE-2015-3268
published 2016-04-12CVE-2015-3268: Cross-site scripting (XSS) vulnerability in the DisplayEntityField.getDescription method in ModelFormField.java in Apache OFBiz before 12.04.06 and 13.07.x…
PriorityP433medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EPSS
9.18%
94.8th percentile
Cross-site scripting (XSS) vulnerability in the DisplayEntityField.getDescription method in ModelFormField.java in Apache OFBiz before 12.04.06 and 13.07.x before 13.07.03 allows remote attackers to inject arbitrary web script or HTML via the description attribute of a display-entity element.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | ofbiz | — | — |
| apache | ofbiz | — | — |
| apache | ofbiz | — | — |
| apache | ofbiz | — | — |
| apache | ofbiz | — | — |
| apache | ofbiz | — | — |
| apache | ofbiz | — | — |
| apache | ofbiz | — | — |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_apache6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apache
Apache ofbiz: CVE-2015-3268
vendor_apache·CVSS 6.1
CVE-2015-3268 [MEDIUM] Apache ofbiz: CVE-2015-3268
Apache ofbiz: CVE-2015-3268
; affected releases: 13.07.02 and earlier versions (13.07.*), 12.04.05 and earlier versions (12.04.*); fixed in 13.07.03 and 12.04.06
GHSA
GHSA-mf45-g8hg-p9g4: Cross-site scripting (XSS) vulnerability in the DisplayEntityField
ghsa_unreviewed·2022-05-14
CVE-2015-3268 [MEDIUM] CWE-79 GHSA-mf45-g8hg-p9g4: Cross-site scripting (XSS) vulnerability in the DisplayEntityField
Cross-site scripting (XSS) vulnerability in the DisplayEntityField.getDescription method in ModelFormField.java in Apache OFBiz before 12.04.06 and 13.07.x before 13.07.03 allows remote attackers to inject arbitrary web script or HTML via the description attribute of a display-entity element.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://ofbiz.apache.org/download.html#vulnerabilitieshttp://packetstormsecurity.com/files/136638/Apache-OFBiz-13.07.02-13.07.01-Information-Disclosure.htmlhttp://www.securityfocus.com/archive/1/538033/100/0/threadedhttp://www.securitytracker.com/id/1035514https://blogs.apache.org/ofbiz/entry/announce_apache_ofbiz_12_04https://blogs.apache.org/ofbiz/entry/announce_apache_ofbiz_13_07https://issues.apache.org/jira/browse/OFBIZ-6506http://ofbiz.apache.org/download.html#vulnerabilitieshttp://packetstormsecurity.com/files/136638/Apache-OFBiz-13.07.02-13.07.01-Information-Disclosure.htmlhttp://www.securityfocus.com/archive/1/538033/100/0/threadedhttp://www.securitytracker.com/id/1035514https://blogs.apache.org/ofbiz/entry/announce_apache_ofbiz_12_04https://blogs.apache.org/ofbiz/entry/announce_apache_ofbiz_13_07https://issues.apache.org/jira/browse/OFBIZ-6506
2016-04-12
Published