CVE-2015-3268: XSS
Cross-site scripting (XSS) vulnerability in the DisplayEntityField.getDescription method in ModelFormField.java in Apache OFBiz before 12.04.06 and 13.07.x before 13.07.03 allows remote attackers to inject arbitrary web script or HTML via the description attribute of a display-entity element.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3268?
CVE-2015-3268 has a medium severity rating due to its potential to allow cross-site scripting attacks.
How do I fix CVE-2015-3268?
To fix CVE-2015-3268, upgrade to Apache OFBiz version 12.04.06 or 13.07.03 and later.
What types of attacks can CVE-2015-3268 enable?
CVE-2015-3268 can enable attackers to inject arbitrary web scripts or HTML code into affected systems.
Which versions of Apache OFBiz are affected by CVE-2015-3268?
CVE-2015-3268 affects Apache OFBiz versions up to and including 12.04.05 and 13.07.02.
How can I identify if my system is vulnerable to CVE-2015-3268?
You can identify vulnerability to CVE-2015-3268 by checking if your Apache OFBiz version is below 12.04.06 or 13.07.03.