CVE-2015-3268 Information
Description
Cross-site scripting (XSS) vulnerability in the DisplayEntityField.getDescription method in ModelFormField.java in Apache OFBiz before 12.04.06 and 13.07.x before 13.07.03 allows remote attackers to inject arbitrary web script or HTML via the description attribute of a display-entity element.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Reference
http://ofbiz.apache.org/download.htmlvulnerabilities http://packetstormsecurity.com/files/136638/Apache-OFBiz-13.07.02-13.07.01-Information-Disclosure.html http://www.securityfocus.com/archive/1/538033/100/0/threaded http://www.securitytracker.com/id/1035514 https://blogs.apache.org/ofbiz/entry/announce_apache_ofbiz_12_04 https://blogs.apache.org/ofbiz/entry/announce_apache_ofbiz_13_07 https://issues.apache.org/jira/browse/OFBIZ-6506
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
CHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
NONE
Base Severity
6.1
Share on: