VYPR
Medium severity6.1NVD Advisory· Published Apr 1, 2020· Updated Jun 17, 2026

CVE-2020-1943

CVE-2020-1943

Description

Data sent with contentId to /control/stream is not sanitized, allowing XSS attacks in Apache OFBiz 16.11.01 to 16.11.07.

Affected products

3
  • Apache/Ofbiz3 versions
    cpe:2.3:a:apache:ofbiz:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:apache:ofbiz:*:*:*:*:*:*:*:*range: >=16.11.01,<=16.11.07
    • (no CPE)range: 16.11.01 to 16.11.07
    • (no CPE)range: 16.11.01 to 16.11.07

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.