Apache OFBiz
cpe:2.3:a:apache:ofbiz:*:*:*:*:*:*:*, +1 more
- < 24.09.06
A vulnerability allowing improper neutralization of special elements in an Expression Language statement has been identified in Apache OFBiz versions prior to 24.09.06. This 'Expression Language Injection' issue could potentially be exploited to manipulate expression evaluation in an unintended manner.
Exploitation of this vulnerability could lead to Server-Side Template Injection (SSTI) in FreeMarker, allowing attackers to execute arbitrary code on the server.
Users are advised to upgrade to Apache OFBiz version 24.09.06 or later, which addresses this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.