cbcvebase.
CVE-2019-0235
published 2020-04-30

CVE-2019-0235: Apache OFBiz 17.12.01 is vulnerable to some CSRF attacks.

PriorityP265high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EXPLOIT
EPSS
32.75%
98.2th percentile
Apache OFBiz 17.12.01 is vulnerable to some CSRF attacks.

Affected

3 ranges
VendorProductVersion rangeFixed in
apacheapache_ofbiz
apacheofbiz
apacheofbiz

Detection & IOCsextracted from sources · hover to see the quote

versionApache OFBiz 17.12.01
versionApache OFBiz before 17.12.03
  • Look for unauthorized POST requests to OFBiz endpoints that originate from cross-origin pages, consistent with a CSRF-based account takeover (e.g., password change or profile update actions submitted without a valid CSRF token).
  • Monitor for password reset / forget-password flows triggered immediately after suspicious form submissions, which may indicate a CSRF account takeover chain.
  • ·Only Apache OFBiz releases prior to 17.12.03 are affected; the vulnerability was fixed in 17.12.03 via commits 82ef7a5 and 62f9b45.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_apache8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.