AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2017-15714

CRITICAL · CVSS 9.8 EPSS 3.29%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2018-01-04 · Last synced 2026-08-04

CyberRota Analysis

This is a critical severity vulnerability with a CVSS score of 9.8. It affects Apache.

CVE
CVE-2017-15714
Severity
CRITICAL
CVSS
9.8
EPSS
3.29%
Apache

Original NVD Description

The BIRT plugin in Apache OFBiz 16.11.01 to 16.11.03 does not escape user input property passed. This allows for code injection by passing that code through the URL. For example by appending this code "__format=%27;alert(%27xss%27)" to the URL an alert window would execute.

Related CVEs

Other vulnerabilities affecting the same vendor(s)