CVE-2022-25813
published 2022-09-02CVE-2022-25813: In Apache OFBiz, versions 18.12.05 and earlier, an attacker acting as an anonymous user of the ecommerce plugin, can insert a malicious content in a message…
PriorityP262high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
67.26%
99.2th percentile
In Apache OFBiz, versions 18.12.05 and earlier, an attacker acting as an anonymous user of the ecommerce plugin, can insert a malicious content in a message “Subject” field from the "Contact us" page. Then a party manager needs to list the communications in the party component to activate the SSTI. A RCE is then possible.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | ofbiz | < 18.12.06 | 18.12.06 |
| apache | ofbiz | — | — |
| apache_software_foundation | apache_ofbiz | Apache OFBiz – 18.12.05 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →SSTI is triggered (and RCE achieved) when a party manager views/lists communications in the party component — alert on party manager sessions that follow anonymous 'Contact us' submissions containing template syntax ↗
- →Vulnerable versions are Apache OFBiz 18.12.05 and earlier; flag any internet-exposed OFBiz instances running these versions ↗
- ·Exploitation is a two-stage, stored SSTI: the payload is stored first by an anonymous user, then triggered only when a privileged party manager views the communications list — detection must cover both stages ↗
- ·Fix was introduced in version 18.12.06 via multiple commits (843b1c7e71, 3797e60375, b24dcff344, 871ce2aa2e, 829e1ca53, 16ed130367, 5cc45e8701); confirm all relevant commits are present when validating patch status ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
vendor_apache7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wrch-3crx-rcpq: In Apache OFBiz, versions 18
ghsa_unreviewed·2022-09-03
CVE-2022-25813 [HIGH] CWE-94 GHSA-wrch-3crx-rcpq: In Apache OFBiz, versions 18
In Apache OFBiz, versions 18.12.05 and earlier, an attacker acting as an anonymous user of the ecommerce plugin, can insert a malicious content in a message “Subject” field from the "Contact us" page. Then a party manager needs to list the communications in the party component to activate the SSTI. A RCE is then possible.
Apache
Apache ofbiz: CVE-2022-25813
vendor_apache·CVSS 7.5
CVE-2022-25813 [HIGH] Apache ofbiz: CVE-2022-25813
Apache ofbiz: CVE-2022-25813
; affected releases before 18.12.06; fixed in 18.12.06 with commits 843b1c7e71 , 3797e60375 , b24dcff344 , 871ce2aa2e , 829e1ca53 , 16ed130367 , 5cc45e8701
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-09-02
Published