Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Vulnerability Details CVE-2020-1943
Data sent with contentId to /control/stream is not sanitized, allowing XSS attacks in Apache OFBiz 16.11.01 to 16.11.07.
Exploit prediction scoring system (EPSS) score
EPSS Score
0.863
EPSS Ranking
99.4%
CVSS Severity
CVSS v3 Score
6.1
CVSS v2 Score
4.3
References
https://lists.apache.org/thread.html/r034123f2767830169fd04c922afb22d2389de6e2faf3a083207202bc%40%3Ccommits.ofbiz.apache.org%3E
https://lists.apache.org/thread.html/r8efd5b62604d849ae2f93b2eb9ce0ce0356a4cf5812deed14030a757%40%3Cdev.ofbiz.apache.org%3E
https://lists.apache.org/thread.html/ra6c011af63d8a8cd8c0b8f72b2b0c392af4d5ed040ba59be344d13fa%40%3Cdev.ofbiz.apache.org%3E
https://s.apache.org/pr5u8
https://lists.apache.org/thread.html/r034123f2767830169fd04c922afb22d2389de6e2faf3a083207202bc%40%3Ccommits.ofbiz.apache.org%3E
https://lists.apache.org/thread.html/r8efd5b62604d849ae2f93b2eb9ce0ce0356a4cf5812deed14030a757%40%3Cdev.ofbiz.apache.org%3E
https://lists.apache.org/thread.html/ra6c011af63d8a8cd8c0b8f72b2b0c392af4d5ed040ba59be344d13fa%40%3Cdev.ofbiz.apache.org%3E
https://s.apache.org/pr5u8
Products affected by CVE-2020-1943
Apache
»
Ofbiz
»
Version:
16.11.01
cpe:2.3:a:apache:ofbiz:16.11.01
Apache
»
Ofbiz
»
Version:
16.11.02
cpe:2.3:a:apache:ofbiz:16.11.02
Apache
»
Ofbiz
»
Version:
16.11.03
cpe:2.3:a:apache:ofbiz:16.11.03
Apache
»
Ofbiz
»
Version:
16.11.04
cpe:2.3:a:apache:ofbiz:16.11.04
Apache
»
Ofbiz
»
Version:
16.11.05
cpe:2.3:a:apache:ofbiz:16.11.05
Apache
»
Ofbiz
»
Version:
16.11.06
cpe:2.3:a:apache:ofbiz:16.11.06
Apache
»
Ofbiz
»
Version:
16.11.07
cpe:2.3:a:apache:ofbiz:16.11.07
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved