cbcvebase.
CVE-2022-25813
published 2022-09-02

CVE-2022-25813: In Apache OFBiz, versions 18.12.05 and earlier, an attacker acting as an anonymous user of the ecommerce plugin, can insert a malicious content in a message…

PriorityP262high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
67.26%
99.2th percentile
In Apache OFBiz, versions 18.12.05 and earlier, an attacker acting as an anonymous user of the ecommerce plugin, can insert a malicious content in a message “Subject” field from the "Contact us" page. Then a party manager needs to list the communications in the party component to activate the SSTI. A RCE is then possible.

Affected

3 ranges
VendorProductVersion rangeFixed in
apacheofbiz< 18.12.0618.12.06
apacheofbiz
apache_software_foundationapache_ofbizApache OFBiz – 18.12.05

Detection & IOCsextracted from sources · hover to see the quote

  • SSTI is triggered (and RCE achieved) when a party manager views/lists communications in the party component — alert on party manager sessions that follow anonymous 'Contact us' submissions containing template syntax
  • Vulnerable versions are Apache OFBiz 18.12.05 and earlier; flag any internet-exposed OFBiz instances running these versions
  • ·Exploitation is a two-stage, stored SSTI: the payload is stored first by an anonymous user, then triggered only when a privileged party manager views the communications list — detection must cover both stages
  • ·Fix was introduced in version 18.12.06 via multiple commits (843b1c7e71, 3797e60375, b24dcff344, 871ce2aa2e, 829e1ca53, 16ed130367, 5cc45e8701); confirm all relevant commits are present when validating patch status

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
vendor_apache7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.