Vulnerability record · CVE-2022-25813 · published 2 September 2022
CVE-2022-25813: Apache OFBiz ecommerce plugin server-side template injection leads to RCE
Apache · Ofbiz
Apache OFBiz 18.12.05 and earlier allows an anonymous user of the ecommerce plugin to inject malicious content into the Subject field of the "Contact us" page. The payload is only executed when a party manager lists the communications in the party component, triggering server-side template injection that can lead to remote code execution.
Description
In Apache OFBiz, versions 18.12.05 and earlier, an attacker acting as an anonymous user of the ecommerce plugin, can insert a malicious content in a message “Subject” field from the "Contact us" page. Then a party manager needs to list the communications in the party component to activate the SSTI. A RCE is then possible.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Automated analysis
high priorityCVSS 7.5 with network reachability and no authentication, plus a very high EPSS score, though exploitation requires a party manager to view the communications list.
What it is
Apache OFBiz 18.12.05 and earlier allows an anonymous user of the ecommerce plugin to inject malicious content into the Subject field of the "Contact us" page. The payload is only executed when a party manager lists the communications in the party component, triggering server-side template injection that can lead to remote code execution.
Impact
An attacker can achieve remote code execution on the OFBiz server, gaining the ability to run arbitrary commands with the application's privileges.
Attack surface
Reachable over the network through the ecommerce plugin's "Contact us" page with no authentication required; a party manager must later view the communications list to activate the injection, so limited user interaction on the victim side is needed.
Exploitation
Not listed in CISA KEV and no public exploit references are tagged, but EPSS is 0.67261 (99.3rd percentile), indicating a high predicted likelihood of exploitation activity.
What to do
- Upgrade Apache OFBiz to a version later than 18.12.05 that contains the fix referenced in the vendor advisory.
- If immediate upgrade is not possible, restrict or disable the ecommerce plugin's "Contact us" page for anonymous users.
- Sanitize and validate the Subject field input on the contact form before it is stored or rendered.
- Limit access to the party component communications listing to trusted administrators only.
- Monitor Apache OFBiz security advisories for follow-up patches or workarounds.
Detection
- Review OFBiz logs for anomalous template expressions or code-like strings in contact form Subject fields.
- Alert on unexpected child processes or command execution spawned by the OFBiz Java process.
- Audit party component communication records for suspicious Subject content submitted from anonymous sessions.
- Monitor for unusual outbound network connections from the OFBiz host following contact form submissions.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.openwall.com/lists/oss-security/2022/09/02/4 | Mailing ListPatchThird Party Advisory |
| https://lists.apache.org/thread/vmj5s0qb59t0lvzf3vol3z1sc3sgyb2b | Mailing ListPatchVendor Advisory |
| http://www.openwall.com/lists/oss-security/2022/09/02/4 | Mailing ListPatchThird Party Advisory |
| https://lists.apache.org/thread/vmj5s0qb59t0lvzf3vol3z1sc3sgyb2b | Mailing ListPatchVendor Advisory |
Track CVE-2022-25813 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-25813), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.