Apache OFBiz Forgot Password Directory Traversal

Discussion in 'News Aggregator' started by Packet Storm, 19 Jun 2024.

  1. Packet Storm

    Packet Storm Guest

    Apache OFBiz versions prior to 18.12.13 are vulnerable to a path traversal vulnerability. The vulnerable endpoint /webtools/control/forgotPassword allows an attacker to access the ProgramExport endpoint which in turn allows for remote code execution in the context of the user running the application.

    Continue reading...
     

Share This Page

Loading...