CVE-2019-10073: XSS
The "Blog", "Forum", "Contact Us" screens of the template "ecommerce" application bundled in Apache OFBiz are weak to Stored XSS attacks. Mitigation: Upgrade to 16.11.06 or manually apply the following commits on branch 16.11: 1858438, 1858543, 1860595 and 1860616
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-10073?
CVE-2019-10073 is a vulnerability in the "Blog", "Forum", and "Contact Us" screens of the "ecommerce" application bundled in Apache OFBiz that allows for Stored XSS attacks.
What is the severity of CVE-2019-10073?
CVE-2019-10073 has a severity rating of 6.1, which is considered medium.
How can I mitigate CVE-2019-10073?
To mitigate CVE-2019-10073, you should upgrade to version 16.11.06 of Apache OFBiz or manually apply the following commits on branch 16.11: 1858438, 1858543, 1860595, and 1860616.
What is the affected software for CVE-2019-10073?
The affected software for CVE-2019-10073 is Apache OFBiz version 16.11.05 and earlier.
What is the CWE for CVE-2019-10073?
The CWE (Common Weakness Enumeration) for CVE-2019-10073 is CWE-79 (Improper Neutralization of Input During Web Page Generation).