CVE-2022-25370: Unauth Stored XSS vulnerability in the Birt plugin of Apache OFBiz
Apache OFBiz uses the Birt plugin (https://eclipse.github.io/birt-website/) to create data visualizations and reports. In Apache OFBiz release 18.12.05, and earlier versions, by leveraging a vulnerability in Birt (https://bugs.eclipse.org/bugs/showbug.cgi?id=538142), an unauthenticated malicious user could perform a stored XSS attack in order to inject a malicious payload and execute it using the stored XSS.
Affected Software
Event History
Frequently Asked Questions
What is the CVE ID of this vulnerability?
CVE-2022-25370.
What is the severity level of CVE-2022-25370?
The severity level of CVE-2022-25370 is medium with a CVSS score of 5.4.
What software is affected by CVE-2022-25370?
Apache OFBiz versions up to and excluding 18.12.06 are affected by CVE-2022-25370.
What is the Common Weakness Enumeration (CWE) ID associated with this vulnerability?
The CWE ID associated with CVE-2022-25370 is CWE-79.
Are there any references for more information about CVE-2022-25370?
Yes, you can find more information about CVE-2022-25370 at the following references: [Reference 1](http://www.openwall.com/lists/oss-security/2022/09/02/8), [Reference 2](http://www.openwall.com/lists/oss-security/2022/09/03/1), [Reference 3](https://lists.apache.org/thread/vrvzokvxqtc4t6d7g8xgz89xpxcvjofh).