← back
CVE-2020-1943observed exploitation

CVE-2020-1943

62Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 97%
from disclosure to weapon
Published on NVDApr 1
VulnCheck+1343d
exploitation probability
97%top 1% of all CVEs
observed exploitation
yesVulnCheck
Data sent with contentId to /control/stream is not sanitized, allowing XSS attacks in Apache OFBiz 16.11.01 to 16.11.07.
Affected products
Apache · Apache OFBiz