CVE-2020-1943
published 2020-04-01CVE-2020-1943: Data sent with contentId to /control/stream is not sanitized, allowing XSS attacks in Apache OFBiz 16.11.01 to 16.11.07.
PriorityP182medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
97.31%
99.9th percentile
Data sent with contentId to /control/stream is not sanitized, allowing XSS attacks in Apache OFBiz 16.11.01 to 16.11.07.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | apache_ofbiz | — | — |
| apache | ofbiz | — | — |
| apache | ofbiz | 16.11.01 – 16.11.07 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor HTTP requests to /control/stream endpoint for unsanitized contentId parameter values containing XSS payloads (e.g., script tags, event handlers). ↗
- →Detection probe expects a 200 HTTP status response with Content-Type: text/html header from the target endpoint.
- ·Vulnerability affects Apache OFBiz versions 16.11.01 through 16.11.07 only; version 17.12.01 and later are patched and should not be targeted by this detection. ↗
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vulncheck6.1MEDIUM
vendor_apache6.1MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pmjx-2693-rfj2: Data sent with contentId to /control/stream is not sanitized, allowing XSS attacks in Apache OFBiz 16
ghsa_unreviewed·2022-05-24
CVE-2020-1943 [MEDIUM] CWE-79 GHSA-pmjx-2693-rfj2: Data sent with contentId to /control/stream is not sanitized, allowing XSS attacks in Apache OFBiz 16
Data sent with contentId to /control/stream is not sanitized, allowing XSS attacks in Apache OFBiz 16.11.01 to 16.11.07.
VulnCheck
Apache OFBiz Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
vulncheck·2020·CVSS 6.1
CVE-2020-1943 [MEDIUM] Apache OFBiz Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Apache OFBiz Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Data sent with contentId to /control/stream is not sanitized, allowing XSS attacks in Apache OFBiz 16.11.01 to 16.11.07.
Affected: Apache OFBiz
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://dashboard.shadowserver.org/statistics/honeypot/vulnerability/map/?day=2023-12-05&host_type=src&vulnerability=cve-2020-1943; https://dashboard.shadowserver.org/statistics/honeypot/vulnerability/map/?day=2023-12-06&host_type=src&vulnerability=cve-2020-1943; https://dashboard.shadowserver.org/statistics/honeypot/vulnerability/map/?day=2023-12-19&host_type=src&vulner
Apache
Apache ofbiz: CVE-2020-1943
vendor_apache·CVSS 6.1
CVE-2020-1943 [MEDIUM] Apache ofbiz: CVE-2020-1943
Apache ofbiz: CVE-2020-1943
; affected releases: from 16.11.01 to 16.11.07; fixed in 17.12.01.
No detection rules found.
Nuclei
Apache OFBiz <=16.11.07 - Cross-Site Scripting
nuclei·CVSS 6.1
CVE-2020-1943 [MEDIUM] Apache OFBiz <=16.11.07 - Cross-Site Scripting
Apache OFBiz "
- type: word
part: header
words:
- "text/html"
- type: status
status:
- 200
# digest: 4a0a004730450221008761a9325fa54cebb5a2d1096f9d28197ecd1e6b2ef18b6dbd2ac68e3f799a3902205eb15c03bfde6d1b825abc633078153491bf45df2ded7c74511ee7f5219d1f21:922c64590222798bb761d5b6d8e72950
https://lists.apache.org/thread.html/r034123f2767830169fd04c922afb22d2389de6e2faf3a083207202bc%40%3Ccommits.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/r8efd5b62604d849ae2f93b2eb9ce0ce0356a4cf5812deed14030a757%40%3Cdev.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/ra6c011af63d8a8cd8c0b8f72b2b0c392af4d5ed040ba59be344d13fa%40%3Cdev.ofbiz.apache.org%3Ehttps://s.apache.org/pr5u8https://lists.apache.org/thread.html/r034123f2767830169fd04c922afb22d2389de6e2faf3a083207202bc%40%3Ccommits.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/r8efd5b62604d849ae2f93b2eb9ce0ce0356a4cf5812deed14030a757%40%3Cdev.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/ra6c011af63d8a8cd8c0b8f72b2b0c392af4d5ed040ba59be344d13fa%40%3Cdev.ofbiz.apache.org%3Ehttps://s.apache.org/pr5u8
2020-04-01
Published
Exploited in the wild