QID 150827
Date Published: 2024-03-11
QID 150827: Apache OFBiz Prior to 18.12.12 Multiple Security Vulnerabilities
Apache OFBiz is an open source enterprise resource planning system. It provides a suite of enterprise applications that integrate and automate many of the business processes of an enterprise.
Affected versions of Apache OFBiz has multiple vulnerabilities:
CVE-2024-23946: Possible path traversal in Apache OFBiz allowing file inclusion.
CVE-2024-25065: Possible path traversal in Apache OFBiz allowing authentication bypass.
Affected Versions:
Apache OFBiz: before 18.12.12.
QID Detection Logic :
This QID sends an HTTP GET request and retrieves a vulnerable version of a OFBiz running on the target application.
Successful exploitation of this vulnerability could allow an unauthenticated attacker to read sensitive files on the target server or access restricted resources by bypassing control checks.
- Apache OFBiz -
ofbiz.apache.org/release-notes-18.12.12.html
CVEs related to QID 150827
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Apache OFBiz |
|