CVE-2017-15714: XSS
The BIRT plugin in Apache OFBiz 16.11.01 to 16.11.03 does not escape user input property passed. This allows for code injection by passing that code through the URL. For example by appending this code "format=%27;alert(%27xss%27)" to the URL an alert window would execute.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-15714?
CVE-2017-15714 is a vulnerability in the BIRT plugin in Apache OFBiz 16.11.01 to 16.11.03 that allows for code injection through user input.
How severe is CVE-2017-15714?
CVE-2017-15714 is classified as critical with a severity rating of 9.8 out of 10.
How does CVE-2017-15714 occur?
CVE-2017-15714 occurs when the BIRT plugin in Apache OFBiz does not properly escape user input, allowing for code injection.
How can CVE-2017-15714 be exploited?
CVE-2017-15714 can be exploited by passing malicious code through the URL to execute arbitrary code.
Is there a fix for CVE-2017-15714?
Yes, the fix for CVE-2017-15714 is available in Apache OFBiz versions 16.11.04 and later.