ZeroHour

CVE-2025-30676

moderate

Cross-Site Scripting (XSS) in Apache OFBiz before 18.12.19

CVSS 3.1
6.1 medium
EPSS
68%p99
Published
()
Modified
AI analysis

CVE-2025-30676 is a cross-site scripting flaw (CWE-80, 'basic XSS') in Apache OFBiz caused by improper neutralization of script-related HTML tags in a web page. Per the CVSS vector (AV:N/AC:L/PR:N/UI:R/S:C), an unauthenticated attacker requires user interaction — typically getting a user to view attacker-influenced content such as a crafted link or page rendered by the OFBiz web interface. If triggered, the attacker's script executes in the victim's browser within the OFBiz origin (scope change), yielding limited confidentiality and integrity impact and no availability impact. All Apache OFBiz releases before 18.12.19 are affected, and users are advised to upgrade to 18.12.19, which fixes the issue. No public proof-of-concept or confirmed in-the-wild exploitation is known yet, but the 67.6% EPSS score (99th percentile) indicates an elevated predicted likelihood of exploitation within 30 days.

What to do: Upgrade to Apache OFBiz 18.12.19 or later, as this release fixes the issue. Until patched, restrict access to the OFBiz web interface (e.g., limit exposure to trusted networks) and review access logs for suspicious crafted URLs or unexpected HTML/script content. Given the high EPSS score, monitor for emerging proofs-of-concept and advisories.

Affected
Apache OFBizbefore 18.12.19
Estimated exposure
moderate≈ a few thousand internet-exposed OFBiz instances (estimate; public internet scans typically surface low thousands of OFBiz servers) — Apache OFBiz is a niche open-source Java ERP/e-commerce framework rather than mass-market software, and internet-wide scans generally find only on the order of a few thousand exposed instances, so exposure is estimated at the 1k–10k…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.19. Users are recommended to upgrade to version 18.12.19, which fixes the issue.

Vendors
apache
Products
ofbiz
Weakness
CWE-80, CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.