CVE-2020-1943
EUVD-2020-1275001.04.2020, 19:15
Data sent with contentId to /control/stream is not sanitized, allowing XSS attacks in Apache OFBiz 16.11.01 to 16.11.07.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| apache | ofbiz | 16.11.01 ≤ 𝑥 ≤ 16.11.07 |
𝑥
= Vulnerable software versions
References