Show filters
141 Total Results
Displaying 81-90 of 141
Sort by:
Attacker Value
Unknown

CVE-2020-13923

Disclosure Date: July 15, 2020 (last updated February 21, 2025)
IDOR vulnerability in the order processing feature from ecommerce component of Apache OFBiz before 17.12.04
Attacker Value
Unknown

CVE-2020-12009

Disclosure Date: June 18, 2020 (last updated February 21, 2025)
A specially crafted communication packet sent to the affected device could cause a denial-of-service condition due to a deserialization vulnerability. This affects: Mitsubishi Electric MC Works64 Version 4.02C (10.95.208.31) and earlier, all versions; Mitsubishi Electric MC Works32 Version 3.00A (9.50.255.02); ICONICS GenBroker64, Platform Services, Workbench, FrameWorX Server v10.96 and prior; ICONICS GenBroker32 v9.5 and prior.
Attacker Value
Unknown

CVE-2019-0235

Disclosure Date: April 30, 2020 (last updated February 21, 2025)
Apache OFBiz 17.12.01 is vulnerable to some CSRF attacks.
Attacker Value
Unknown

CVE-2019-12425

Disclosure Date: April 30, 2020 (last updated February 21, 2025)
Apache OFBiz 17.12.01 is vulnerable to Host header injection by accepting arbitrary host
Attacker Value
Unknown

CVE-2020-1943

Disclosure Date: April 01, 2020 (last updated February 21, 2025)
Data sent with contentId to /control/stream is not sanitized, allowing XSS attacks in Apache OFBiz 16.11.01 to 16.11.07.
Attacker Value
Unknown

CVE-2019-12426

Disclosure Date: February 06, 2020 (last updated November 08, 2023)
an unauthenticated user could get access to information of some backend screens by invoking setSessionLocale in Apache OFBiz 16.11.01 to 16.11.06
Attacker Value
Unknown

CVE-2011-3600

Disclosure Date: November 26, 2019 (last updated November 27, 2024)
The /webtools/control/xmlrpc endpoint in OFBiz XML-RPC event handler is exposed to External Entity Injection by passing DOCTYPE declarations with executable payloads that discloses the contents of files in the filesystem. In addition, it can also be used to probe for open network ports, and figure out from returned error messages whether a file exists or not. This affects OFBiz 16.11.01 to 16.11.04.
Attacker Value
Unknown

CVE-2015-9499

Disclosure Date: October 22, 2019 (last updated November 27, 2024)
The Showbiz Pro plugin through 1.7.1 for WordPress has PHP code execution by uploading a .php file within a ZIP archive.
Attacker Value
Unknown

CVE-2019-0189

Disclosure Date: September 11, 2019 (last updated November 08, 2023)
The java.io.ObjectInputStream is known to cause Java serialisation issues. This issue here is exposed by the "webtools/control/httpService" URL, and uses Java deserialization to perform code execution. In the HttpEngine, the value of the request parameter "serviceContext" is passed to the "deserialize" method of "XmlSerializer". Apache Ofbiz is affected via two different dependencies: "commons-beanutils" and an out-dated version of "commons-fileupload" Mitigation: Upgrade to 16.11.06 or manually apply the commits from OFBIZ-10770 and OFBIZ-10837 on branch 16
Attacker Value
Unknown

CVE-2019-10074

Disclosure Date: September 11, 2019 (last updated November 08, 2023)
An RCE is possible by entering Freemarker markup in an Apache OFBiz Form Widget textarea field when encoding has been disabled on such a field. This was the case for the Customer Request "story" input in the Order Manager application. Encoding should not be disabled without good reason and never within a field that accepts user input. Mitigation: Upgrade to 16.11.06 or manually apply the following commit on branch 16.11: r1858533