[ { "id": 583474404, "name": "CVE-2022-25813", "full_name": "Live-Hack-CVE\/CVE-2022-25813", "owner": { "login": "Live-Hack-CVE", "id": 121191732, "avatar_url": "https:\/\/avatars.githubusercontent.com\/u\/121191732?v=4", "html_url": "https:\/\/github.com\/Live-Hack-CVE" }, "html_url": "https:\/\/github.com\/Live-Hack-CVE\/CVE-2022-25813", "description": "In Apache OFBiz, versions 18.12.05 and earlier, an attacker acting as an anonymous user of the ecommerce plugin, can insert a malicious content in a message “Subject” field from the \"Contact us\" page. Then a party manager needs to list the communications in the party component to activate the SSTI. A RCE is then possib CVE project by @Sn0wAlice", "fork": false, "created_at": "2022-12-29T22:19:30Z", "updated_at": "2022-12-29T22:19:30Z", "pushed_at": "2022-12-29T22:19:32Z", "stargazers_count": 0, "watchers_count": 0, "has_discussions": false, "forks_count": 0, "allow_forking": true, "is_template": false, "web_commit_signoff_required": false, "topics": [], "visibility": "public", "forks": 0, "watchers": 0, "score": 0 } ]