Description
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.19. Users are recommended to upgrade to version 18.12.19, which fixes the issue.
Problem types
CWE-80 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
Product status
Any version before 18.12.19
Credits
Khaled Nassar (@mindpatch)
References
www.openwall.com/lists/oss-security/2025/04/01/5
ofbiz.apache.org/download.html
ofbiz.apache.org/security.html
issues.apache.org/jira/browse/OFBIZ-13219
lists.apache.org/thread/8d718qt8dqthnw1gmyxsq8glfdjklnjf
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.