Unauth Stored XSS vulnerability in the Birt plugin of Apache OFBiz
Vulnerability Description
Apache OFBiz uses the Birt plugin (https://eclipse.github.io/birt-website/) to create data visualizations and reports. In Apache OFBiz release 18.12.05, and earlier versions, by leveraging a vulnerability in Birt (https://bugs.eclipse.org/bugs/show_bug.cgi?id=538142), an unauthenticated malicious user could perform a stored XSS attack in order to inject a malicious payload and execute it using the stored XSS.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-25370
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Nikita Podotykin from Positive Technologies <npodotykin@ptsecurity.com>
- Positive Technologies zeroday <zeroday@ptsecurity.com>
References
More from Apache Software Foundation
View All →Affected Vendor
Apache Software Foundation
View all reports →