VYPR

OFBiz ecommerce plugin

by Apache

CVEs (1)

  • CVE-2022-25813HigSep 2, 2022
    risk 0.54cvss 7.5epss 0.67

    In Apache OFBiz, versions 18.12.05 and earlier, an attacker acting as an anonymous user of the ecommerce plugin, can insert a malicious content in a message “Subject” field from the "Contact us" page. Then a party manager needs to list the communications in the party…