{"api_version":"1","generated_at":"2026-07-23T08:53:09+00:00","cve":"CVE-2015-3268","urls":{"html":"https://cve.report/CVE-2015-3268","api":"https://cve.report/api/cve/CVE-2015-3268.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2015-3268","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2015-3268"},"summary":{"title":"CVE-2015-3268","description":"Cross-site scripting (XSS) vulnerability in the DisplayEntityField.getDescription method in ModelFormField.java in Apache OFBiz before 12.04.06 and 13.07.x before 13.07.03 allows remote attackers to inject arbitrary web script or HTML via the description attribute of a display-entity element.","state":"PUBLISHED","assigner":"redhat","published_at":"2016-04-12 14:59:00","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"6.1","severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"https://issues.apache.org/jira/browse/OFBIZ-6506","name":"https://issues.apache.org/jira/browse/OFBIZ-6506","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[OFBIZ-6506] XSS vulnerability in OFBiz forms and screens especially in display-entity component - ASF JIRA","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://ofbiz.apache.org/download.html#vulnerabilities","name":"http://ofbiz.apache.org/download.html#vulnerabilities","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Apache OFBiz - Download Releases","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://blogs.apache.org/ofbiz/entry/announce_apache_ofbiz_12_04","name":"https://blogs.apache.org/ofbiz/entry/announce_apache_ofbiz_12_04","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[ANNOUNCE} Apache OFBiz 12.04.06 Released : OFBiz","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1035514","name":"http://www.securitytracker.com/id/1035514","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Apache OFBiz Input Validation Flaw Lets Remote Conduct Cross-Site Scripting Attacks - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/538033/100/0/threaded","name":"http://www.securityfocus.com/archive/1/538033/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://packetstormsecurity.com/files/136638/Apache-OFBiz-13.07.02-13.07.01-Information-Disclosure.html","name":"http://packetstormsecurity.com/files/136638/Apache-OFBiz-13.07.02-13.07.01-Information-Disclosure.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Apache OFBiz 13.07.02 / 13.07.01 Information Disclosure ≈ Packet Storm","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://blogs.apache.org/ofbiz/entry/announce_apache_ofbiz_13_07","name":"https://blogs.apache.org/ofbiz/entry/announce_apache_ofbiz_13_07","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"[ANNOUNCE] Apache OFBiz 13.07.03 Released : OFBiz","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2015-3268","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2015-3268","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2015","cve_id":"3268","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"apache","cpe5":"ofbiz","cpe6":"12.04.01","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"3268","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"apache","cpe5":"ofbiz","cpe6":"12.04.02","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"3268","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"apache","cpe5":"ofbiz","cpe6":"12.04.03","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"3268","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"apache","cpe5":"ofbiz","cpe6":"12.04.04","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"3268","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"apache","cpe5":"ofbiz","cpe6":"12.04.05","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"3268","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"apache","cpe5":"ofbiz","cpe6":"13.07.01","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"3268","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"apache","cpe5":"ofbiz","cpe6":"13.07.02","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T05:39:32.040Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://ofbiz.apache.org/download.html#vulnerabilities"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://blogs.apache.org/ofbiz/entry/announce_apache_ofbiz_12_04"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://issues.apache.org/jira/browse/OFBIZ-6506"},{"name":"1035514","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1035514"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://blogs.apache.org/ofbiz/entry/announce_apache_ofbiz_13_07"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://packetstormsecurity.com/files/136638/Apache-OFBiz-13.07.02-13.07.01-Information-Disclosure.html"},{"name":"20160408 CVE-2015-3268: Apache OFBiz information disclosure vulnerability","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/538033/100/0/threaded"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2016-04-08T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in the DisplayEntityField.getDescription method in ModelFormField.java in Apache OFBiz before 12.04.06 and 13.07.x before 13.07.03 allows remote attackers to inject arbitrary web script or HTML via the description attribute of a display-entity element."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-09T18:57:01.000Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://ofbiz.apache.org/download.html#vulnerabilities"},{"tags":["x_refsource_CONFIRM"],"url":"https://blogs.apache.org/ofbiz/entry/announce_apache_ofbiz_12_04"},{"tags":["x_refsource_CONFIRM"],"url":"https://issues.apache.org/jira/browse/OFBIZ-6506"},{"name":"1035514","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1035514"},{"tags":["x_refsource_CONFIRM"],"url":"https://blogs.apache.org/ofbiz/entry/announce_apache_ofbiz_13_07"},{"tags":["x_refsource_MISC"],"url":"http://packetstormsecurity.com/files/136638/Apache-OFBiz-13.07.02-13.07.01-Information-Disclosure.html"},{"name":"20160408 CVE-2015-3268: Apache OFBiz information disclosure vulnerability","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/538033/100/0/threaded"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"secalert@redhat.com","ID":"CVE-2015-3268","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in the DisplayEntityField.getDescription method in ModelFormField.java in Apache OFBiz before 12.04.06 and 13.07.x before 13.07.03 allows remote attackers to inject arbitrary web script or HTML via the description attribute of a display-entity element."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://ofbiz.apache.org/download.html#vulnerabilities","refsource":"CONFIRM","url":"http://ofbiz.apache.org/download.html#vulnerabilities"},{"name":"https://blogs.apache.org/ofbiz/entry/announce_apache_ofbiz_12_04","refsource":"CONFIRM","url":"https://blogs.apache.org/ofbiz/entry/announce_apache_ofbiz_12_04"},{"name":"https://issues.apache.org/jira/browse/OFBIZ-6506","refsource":"CONFIRM","url":"https://issues.apache.org/jira/browse/OFBIZ-6506"},{"name":"1035514","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1035514"},{"name":"https://blogs.apache.org/ofbiz/entry/announce_apache_ofbiz_13_07","refsource":"CONFIRM","url":"https://blogs.apache.org/ofbiz/entry/announce_apache_ofbiz_13_07"},{"name":"http://packetstormsecurity.com/files/136638/Apache-OFBiz-13.07.02-13.07.01-Information-Disclosure.html","refsource":"MISC","url":"http://packetstormsecurity.com/files/136638/Apache-OFBiz-13.07.02-13.07.01-Information-Disclosure.html"},{"name":"20160408 CVE-2015-3268: Apache OFBiz information disclosure vulnerability","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/538033/100/0/threaded"}]}}}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2015-3268","datePublished":"2016-04-12T14:00:00.000Z","dateReserved":"2015-04-10T00:00:00.000Z","dateUpdated":"2024-08-06T05:39:32.040Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2016-04-12 14:59:00","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:apache:ofbiz:12.04.01:*:*:*:*:*:*:*","matchCriteriaId":"7A557337-D8FD-47F4-9E66-9A642B834E7D"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:ofbiz:12.04.02:*:*:*:*:*:*:*","matchCriteriaId":"50FFA2EC-0680-4ECA-BFCA-CE6EAF5611F3"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:ofbiz:12.04.03:*:*:*:*:*:*:*","matchCriteriaId":"4BB02CEF-3431-4138-AC3D-27363073C29C"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:ofbiz:12.04.04:*:*:*:*:*:*:*","matchCriteriaId":"BFDA615A-5A77-4F1B-881B-B3B675082CB7"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:ofbiz:12.04.05:*:*:*:*:*:*:*","matchCriteriaId":"C0442A7B-10C0-4C74-9C61-BAEDA6404D73"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:ofbiz:13.07.01:*:*:*:*:*:*:*","matchCriteriaId":"A5435A8B-111C-4512-ABAB-9B89503C12E4"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:ofbiz:13.07.02:*:*:*:*:*:*:*","matchCriteriaId":"F6E714B9-7B4D-4CC9-8280-1573D82E293A"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2015","CveId":"3268","Ordinal":"1","Title":"CVE-2015-3268","CVE":"CVE-2015-3268","Year":"2015"},"notes":[{"CveYear":"2015","CveId":"3268","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in the DisplayEntityField.getDescription method in ModelFormField.java in Apache OFBiz before 12.04.06 and 13.07.x before 13.07.03 allows remote attackers to inject arbitrary web script or HTML via the description attribute of a display-entity element.","Type":"Description","Title":"CVE-2015-3268"},{"CveYear":"2015","CveId":"3268","Ordinal":"2","NoteData":"2016-04-12","Type":"Other","Title":"Published"},{"CveYear":"2015","CveId":"3268","Ordinal":"3","NoteData":"2018-10-09","Type":"Other","Title":"Modified"}]}}}