CVE-2020-1943
01.04.2020, 19:15
Data sent with contentId to /control/stream is not sanitized, allowing XSS attacks in Apache OFBiz 16.11.01 to 16.11.07.
Vendor | Product | Version |
---|---|---|
apache | ofbiz | 16.11.01 ≤ 𝑥 ≤ 16.11.07 |
𝑥
= Vulnerable software versions
References