VYPR
Unrated severityNVD Advisory· Published Apr 1, 2020· Updated Aug 4, 2024

CVE-2020-1943

CVE-2020-1943

Description

Data sent with contentId to /control/stream is not sanitized, allowing XSS attacks in Apache OFBiz 16.11.01 to 16.11.07.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.