Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-50223

Опубликовано: 10 июн. 2026
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz allows a low-privileged authenticated user with Content/DataResource editing privileges to perform template injection attacks that could lead to Remote Code Execution.

This issue affects Apache OFBiz: before 24.09.07.

Users are recommended to upgrade to version 24.09.07, which fixes the issue.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:apache:ofbiz:*:*:*:*:*:*:*:*
Версия до 24.09.07 (исключая)

EPSS

Процентиль: 48%
0.00657
Низкий

8.8 High

CVSS3

Дефекты

CWE-94

Связанные уязвимости

github
3 месяца назад

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz allows a low-privileged authenticated user with Content/DataResource editing privileges to perform template injection attacks that could lead to Remote Code Execution. This issue affects Apache OFBiz: before 24.09.07. Users are recommended to upgrade to version 24.09.07, which fixes the issue.

EPSS

Процентиль: 48%
0.00657
Низкий

8.8 High

CVSS3

Дефекты

CWE-94