First published: Wed Sep 11 2019(Updated: )
The "Blog", "Forum", "Contact Us" screens of the template "ecommerce" application bundled in Apache OFBiz are weak to Stored XSS attacks. Mitigation: Upgrade to 16.11.06 or manually apply the following commits on branch 16.11: 1858438, 1858543, 1860595 and 1860616
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache OFBiz | >=16.11.01<=16.11.05 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-10073 is a vulnerability in the "Blog", "Forum", and "Contact Us" screens of the "ecommerce" application bundled in Apache OFBiz that allows for Stored XSS attacks.
CVE-2019-10073 has a severity rating of 6.1, which is considered medium.
To mitigate CVE-2019-10073, you should upgrade to version 16.11.06 of Apache OFBiz or manually apply the following commits on branch 16.11: 1858438, 1858543, 1860595, and 1860616.
The affected software for CVE-2019-10073 is Apache OFBiz version 16.11.05 and earlier.
The CWE (Common Weakness Enumeration) for CVE-2019-10073 is CWE-79 (Improper Neutralization of Input During Web Page Generation).