CVE-2016-6800
Summary
| CVE | CVE-2016-6800 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-08-30 17:29:00 UTC |
| Updated | 2023-11-07 02:34:00 UTC |
| Description | The default configuration of the Apache OFBiz framework offers a blog functionality. Different users are able to operate blogs which are related to specific parties. In the form field for the creation of new blog articles the user input of the summary field as well as the article field is not properly sanitized. It is possible to inject arbitrary JavaScript code in these form fields. This code gets executed from the browser of every user who is visiting this article. Mitigation: Upgrade to Apache OFBiz 16.11.01. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Ofbiz | 11.04 | All | All | All |
| Application | Apache | Ofbiz | 11.04.01 | All | All | All |
| Application | Apache | Ofbiz | 11.04.02 | All | All | All |
| Application | Apache | Ofbiz | 11.04.03 | All | All | All |
| Application | Apache | Ofbiz | 11.04.04 | All | All | All |
| Application | Apache | Ofbiz | 11.04.05 | All | All | All |
| Application | Apache | Ofbiz | 11.04.06 | All | All | All |
| Application | Apache | Ofbiz | 12.04 | All | All | All |
| Application | Apache | Ofbiz | 12.04.01 | All | All | All |
| Application | Apache | Ofbiz | 12.04.02 | All | All | All |
| Application | Apache | Ofbiz | 12.04.03 | All | All | All |
| Application | Apache | Ofbiz | 12.04.04 | All | All | All |
| Application | Apache | Ofbiz | 12.04.05 | All | All | All |
| Application | Apache | Ofbiz | 12.04.06 | All | All | All |
| Application | Apache | Ofbiz | 13.07 | All | All | All |
| Application | Apache | Ofbiz | 13.07.01 | All | All | All |
| Application | Apache | Ofbiz | 13.07.02 | All | All | All |
| Application | Apache | Ofbiz | 13.07.03 | All | All | All |
| Application | Apache | Ofbiz | 11.04 | All | All | All |
| Application | Apache | Ofbiz | 11.04.01 | All | All | All |
| Application | Apache | Ofbiz | 11.04.02 | All | All | All |
| Application | Apache | Ofbiz | 11.04.03 | All | All | All |
| Application | Apache | Ofbiz | 11.04.04 | All | All | All |
| Application | Apache | Ofbiz | 11.04.05 | All | All | All |
| Application | Apache | Ofbiz | 11.04.06 | All | All | All |
| Application | Apache | Ofbiz | 12.04 | All | All | All |
| Application | Apache | Ofbiz | 12.04.01 | All | All | All |
| Application | Apache | Ofbiz | 12.04.02 | All | All | All |
| Application | Apache | Ofbiz | 12.04.03 | All | All | All |
| Application | Apache | Ofbiz | 12.04.04 | All | All | All |
| Application | Apache | Ofbiz | 12.04.05 | All | All | All |
| Application | Apache | Ofbiz | 12.04.06 | All | All | All |
| Application | Apache | Ofbiz | 13.07 | All | All | All |
| Application | Apache | Ofbiz | 13.07.01 | All | All | All |
| Application | Apache | Ofbiz | 13.07.02 | All | All | All |
| Application | Apache | Ofbiz | 13.07.03 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Pony Mail! | lists.apache.org | ||
| [SECURITY] CVE-2016-6800 Apache OFBiz blog stored XSS vulnerability | MLIST | s.apache.org | Mailing List, Mitigation, Vendor Advisory |
| Pony Mail! | MLIST | lists.apache.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.