Apache OFBiz Path Traversal Vulnerability

Strike ID:
E24-itm91
CVSS:
9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
False Positive:
f
Variants:
3
Year:
2024

Description

This strike exploits a path traversal vulnerability in Apache OFBiz. The vulnerability arises from inadequate sanitization of input at the vulnerable endpoint /webtools/control/forgotPassword. An attacker can exploit this endpoint to access the ProgramExport functionality, which can then be leveraged for remote code execution. Successful exploitation allows unauthenticated remote attackers to execute arbitrary code with the privileges of the user running the vulnerable server.

CVE

References