CVE-2024-48962

Published Nov 18, 2024

Last updated 2 months ago

Overview

Description
Improper Control of Generation of Code ('Code Injection'), Cross-Site Request Forgery (CSRF), : Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.17. Users are recommended to upgrade to version 18.12.17, which fixes the issue.
Source
security@apache.org
NVD status
Analyzed

Risk scores

CVSS 4.0

Type
Secondary
Base score
8.9
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:H/U:Amber
Severity
HIGH

CVSS 3.1

Type
Primary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

security@apache.org
CWE-94
nvd@nist.gov
CWE-94

Social media

Hype score
Not currently trending
  1. Threat Alert: CVE-2024-47208 &amp- CVE-2024-48962: Apache OFBiz Exposed to Remote Code Executi CVE-2024-47208 CVE-2024-48962 Severity: ⚠️ Critical Maturity: 💢 Emerging Learn more: https://t.co/NMDqhN5sxp #CyberSecurity #ThreatIntel #InfoSec

    @fletch_ai

    21 Nov 2024

    13 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. CVE-2024-47208 & CVE-2024-48962: Apache OFBiz Exposed to Remote Code Execution https://t.co/7btTCI0isI

    @Dinosn

    20 Nov 2024

    1632 Impressions

    2 Retweets

    4 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 🚨🚨Apache OFBiz Exposed to Remote Code Execution CVE-2024-47208: Exploiting Groovy Expressions for Remote Code Execution CVE-2024-48962: Bypassing SameSite Protections for Cross-Site Attacks ZoomEye Dork👉app="Apache OFBiz" 848 results are found on https://t.co/2EQoXN52Vx.… htt

    @zoomeye_team

    20 Nov 2024

    427 Impressions

    0 Retweets

    5 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  4. Apache OFBiz Exposed to Remote Code Execution Urgent security updates for #Apache #OFBiz: Learn about the critical vulnerabilities (CVE-2024-47208 and CVE-2024-48962) and how they can compromise your business https://t.co/VssgroUXKB

    @the_yellow_fall

    20 Nov 2024

    64 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. [CVE-2024-48962: HIGH] Critical cyber security vulnerabilities found in Apache OFBiz before version 18.12.17. Upgrade immediately to patch Code Injection and CSRF flaws. Stay protected!#cybersecurity,#vulnerability https://t.co/fkj5gU8zEv https://t.co/lBKruW3wyR

    @CveFindCom

    18 Nov 2024

    43 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. CVE-2024-48962 Improper Control of Generation of Code ('Code Injection'), Cross-Site Request Forgery (CSRF), : Improper Neutralization of Special Elements Used in a Template Engine … https://t.co/4YEaswlvBk

    @CVEnew

    18 Nov 2024

    311 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. CVE-2024-48962: Apache OFBiz: Bypass SameSite restrictions with target redirection using URL parameters (SSTI and CSRF leading to RCE) https://t.co/LbIs6VrXYy CVE-2024-47208: Apache OFBiz: URLs allowing remote use of Groovy expressions, leading to RCE https://t.co/khwrnYJ2NR

    @oss_security

    16 Nov 2024

    253 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. CVE-2024-48962 Affected versions: - Apache OFBiz before 18.12.17 Description: Improper Control of Generation of Code ('Code Injection'), Cross-Site Request Forgery (CSRF), Improper Neutralization of Special ... https://t.co/O5WXtnixRV

    @VulmonFeeds

    16 Nov 2024

    48 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations