Cross-site scripting in OFBiz - CVE-2020-9496
Published: July 15, 2020 / Updated: June 27, 2023
Vulnerability identifier: #VU34153
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2020-9496
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
Affected software
OFBiz
How to mitigate CVE-2020-9496
Install update from vendor's website.
Links to Public Exploits and PoC-codes
- Exploit #9152 - CVE-2020-9496 (ApacheOfBiz 17.12.01 Remote Code Execution) (June 27, 2023)
- Exploit #8258 - CVE-2020-9496 (ApacheOfBiz 17.12.01 - Unauthorized Remote Code Executión ) (August 16, 2022)
- Exploit #7069 - ApacheOfBiz 17.12.01 - Remote Command Execution (RCE) via Unsafe Deserialization of XMLRPC arguments (November 25, 2021)
- Exploit #6598 - CVE-2020-9496 () (August 5, 2021)
- Exploit #5536 - CVE-2020-9496 (XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03) (June 6, 2021)
- Exploit #5406 - ofbiz-poc (CVE-2020-9496和CVE-2021-26295利用dnslog批量验证漏洞poc及exp) (May 13, 2021)
- Exploit #5376 - Apache OFBiz XML-RPC Java Deserialization (May 9, 2021)
- Exploit #5348 - CVE-2020-9496 (CVE-2020-9496 manual exploit) (May 9, 2021)
- Exploit #5335 - CVE-2020-9496 (Apache OFBiz unsafe deserialization of XMLRPC arguments) (May 3, 2021)
- Exploit #4498 - Apache OFBiz XML-RPC Java Deserialization (August 17, 2020)