Back to search
CVE-2014-0232
Published: Aug 22, 2014
Modified: Aug 6, 2024
PUBLISHED
Description
Multiple cross-site scripting (XSS) vulnerabilities in framework/common/webcommon/includes/messages.ftl in Apache OFBiz 11.04.01 before 11.04.05 and 12.04.01 before 12.04.04 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, which are not properly handled in a (1) result or (2) error message.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
[oss-security] 20140819 [CVE-2014-0232] Apache OFBiz Cross-site scripting (XSS) vulnerability
mailing-list
x_refsource_MLIST
60807
third-party-advisory
x_refsource_SECUNIA
http://ofbiz.apache.org/download.html#vulnerabilities
x_refsource_CONFIRM
1030739
vdb-entry
x_refsource_SECTRACK
apache-ofbiz-cve20140232-xss(95356)
vdb-entry
x_refsource_XF
20140819 [CVE-2014-0232] Apache OFBiz Cross-site scripting (XSS) vulnerability
mailing-list
x_refsource_BUGTRAQ
69286
vdb-entry
x_refsource_BID
http://svn.apache.org/viewvc?view=revision&revision=r1608698
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now