First published: Sat Nov 16 2024(Updated: )
Improper Control of Generation of Code ('Code Injection'), Cross-Site Request Forgery (CSRF), : Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.17. Users are recommended to upgrade to version 18.12.17, which fixes the issue.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache OFBiz | <18.12.17 | |
Apache OFBiz | <18.12.17 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-48962 is classified as a high severity vulnerability due to its potential for code injection and cross-site request forgery.
To resolve CVE-2024-48962, users should upgrade Apache OFBiz to version 18.12.17 or later.
CVE-2024-48962 can lead to unauthorized code execution and facilitate CSRF attacks, compromising the integrity of the application.
CVE-2024-48962 affects all versions of Apache OFBiz prior to 18.12.17.
The patch for CVE-2024-48962 is included in the upgrade to Apache OFBiz version 18.12.17.