SonicALERT
Search

Sonicwall Signatures

 

Go to All Categories list.


  Apache OFBiz Scrum plugin Code Injection 2

Category: WEB-ATTACKS      

Improper Control of Generation of Code (Code Injection) vulnerability leading to a possible RCE in Apache OFBiz scrum plugin. This issue affects Apache OFBiz: before 24.09.02 only when the scrum plugin is used. Even unauthenticated attackers can exploit this vulnerability. Users are recommended to upgrade to version 24.09.02, which fixes the issue.


Relevant Information