Apache OFBiz
cpe:2.3:a:apache:ofbiz:*:*:*:*:*:*:*, +1 more
- >= 18.12.17, < 18.12.18
A server-side template injection vulnerability has been identified in Apache OFBiz versions 18.12.17 prior to 18.12.18. This issue, which is a regression between these two versions, arises from improper neutralization of special elements used in the Freemarker template engine. As a result, it could potentially lead to remote code execution.
Exploitation of this vulnerability could allow for server-side template injection, with the possibility of remote code execution, particularly in the e-commerce plugin.
Users are advised to upgrade to Apache OFBiz version 18.12.18, which addresses this vulnerability. Instructions for downloading the latest version can be found on the Apache OFBiz website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.