CVE-2025-26865
Apache OFBiz: Server-Side Template Injection affecting the ecommerce plugin leading to possible RCE
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz. This issue affects Apache OFBiz: from 18.12.17 before 18.12.18. It's a regression between 18.12.17 and 18.12.18.
In case you use something like that, which is not recommended!
For security, only official releases should be used. In other words, if you use 18.12.17 you are still safe.
The version 18.12.17 is not a affected.
But something between 18.12.17 and 18.12.18 is. In that case, users are recommended to upgrade to version 18.12.18, which fixes the issue.
Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz. This issue affects Apache OFBiz: from 18.12.17 before 18.12.18. It's a regression between 18.12.17 and 18.12.18. In case you use something like that, which is not recommended! For security, only official releases should be used. In other words, if you use 18.12.17 you are still safe. The version 18.12.17 is not a affected. But something between 18.12.17 and 18.12.18 is. In that case, users are recommended to upgrade to version 18.12.18, which fixes the issue.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2025-02-17 CVE Reserved
- 2025-03-10 CVE Published
- 2025-03-11 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-1336: Improper Neutralization of Special Elements Used in a Template Engine
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
https://issues.apache.org/jira/browse/OFBIZ-12594 | Issue Tracking | |
https://ofbiz.apache.org/download.html | Mitigation | |
http://www.openwall.com/lists/oss-security/2025/03/07/1 |
|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://ofbiz.apache.org/security.html | 2025-03-10 |
URL | Date | SRC |
---|---|---|
https://lists.apache.org/thread/prb48ztk01bflyyjbl6p56wlcc1n5sz7 | 2025-03-10 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apache Software Foundation Search vendor "Apache Software Foundation" | Apache OFBiz Search vendor "Apache Software Foundation" for product "Apache OFBiz" | >= 18.12.17 < 18.12.18 Search vendor "Apache Software Foundation" for product "Apache OFBiz" and version " >= 18.12.17 < 18.12.18" | en |
Affected
|