Details
-
Bug
-
Status: Closed
-
Major
-
Resolution: Duplicate
-
None
-
None
-
None
Description
Hi,
There is a Cross Site Scripting vulnerability in OFBiz login form that allow a attacker to stole user's data.
PoC:
- Redirection to another site:
- BeEF injection:
Same thing using "PASSWORD" instead of "USERNAME".
Bye
Attachments
Issue Links
- is a clone of
-
OFBIZ-178 Cross site scripting vulnerability in Forum
- Closed
- is part of
-
OFBIZ-1525 Issue to group security concerns
- Open