CVE-2020-9496: XSS
Published Jul 15, 2020
·Updated
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
Affected Software
1 affected component
Apache OFBiz=17.12.03
Remediation
Event History
Jul 15, 2020
CVE Published
via MITRE·03:39 PM
Data Sourced
via MITRE·03:39 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-9496?
The severity of CVE-2020-9496 is medium.
2
What is the vulnerability description of CVE-2020-9496?
CVE-2020-9496 is a vulnerability in Apache OFBiz 17.12.03 that allows for unsafe deserialization and Cross-Site Scripting issues in XML-RPC requests.
3
What software version is affected by CVE-2020-9496?
Apache OFBiz version 17.12.03 is affected by CVE-2020-9496.
4
How can this vulnerability be exploited?
CVE-2020-9496 can be exploited through XML-RPC requests by performing unsafe deserialization and injecting malicious scripts.
5
Are there any references available for CVE-2020-9496?
Yes, you can find references for CVE-2020-9496 at the following links: [link1], [link2], [link3].