Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-862q-5rrg-cc9p

Опубликовано: 11 июн. 2026
Источник: github
Github: Не прошло ревью

Описание

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz allows a low-privileged authenticated user with Content/DataResource editing privileges to perform template injection attacks that could lead to Remote Code Execution.

This issue affects Apache OFBiz: before 24.09.07.

Users are recommended to upgrade to version 24.09.07, which fixes the issue.

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz allows a low-privileged authenticated user with Content/DataResource editing privileges to perform template injection attacks that could lead to Remote Code Execution.

This issue affects Apache OFBiz: before 24.09.07.

Users are recommended to upgrade to version 24.09.07, which fixes the issue.

EPSS

Процентиль: 48%
0.00657
Низкий

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 8.8
nvd
2 месяца назад

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz allows a low-privileged authenticated user with Content/DataResource editing privileges to perform template injection attacks that could lead to Remote Code Execution. This issue affects Apache OFBiz: before 24.09.07. Users are recommended to upgrade to version 24.09.07, which fixes the issue.

EPSS

Процентиль: 48%
0.00657
Низкий

Дефекты

CWE-94