CVE-2024-48962: Apache OFBiz: Bypass SameSite restrictions with target redirection using URL parameters (SSTI and CSRF leading to RCE)
Improper Control of Generation of Code ('Code Injection'), Cross-Site Request Forgery (CSRF), : Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 18.12.17.
Users are recommended to upgrade to version 18.12.17, which fixes the issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-48962?
CVE-2024-48962 is classified as a high severity vulnerability due to its potential for code injection and cross-site request forgery.
How do I fix CVE-2024-48962?
To resolve CVE-2024-48962, users should upgrade Apache OFBiz to version 18.12.17 or later.
What are the impacts of CVE-2024-48962?
CVE-2024-48962 can lead to unauthorized code execution and facilitate CSRF attacks, compromising the integrity of the application.
Which versions of Apache OFBiz are affected by CVE-2024-48962?
CVE-2024-48962 affects all versions of Apache OFBiz prior to 18.12.17.
Is there a patch available for CVE-2024-48962?
The patch for CVE-2024-48962 is included in the upgrade to Apache OFBiz version 18.12.17.