"[SECURITY] CVE-2017-15714 Apache OFBiz BIRT code vulnerability"

2018-01-04 Thread Taher Alkhateeb
Severity: Important Vendor: The Apache Software Foundation Versions Affected: OFBiz 16.11.01 to 16.11.03 Description: The BIRT plugin in Apache OFBiz does not escape user input property passed. This allows for code injection by passing that code through the URL. For example by appending this cod

[SECURITY] CVE-2017-15714 Apache OFBiz BIRT code vulnerability

2018-01-03 Thread Taher Alkhateeb
Severity: Important Vendor: The Apache Software Foundation Versions Affected: OFBiz 16.11.01 to 16.11.03 Description: The BIRT plugin in Apache OFBiz does not escape user input property passed. This allows for code injection by passing that code through the URL. For example by appending this cod