#VU95407 Improper Authorization in OFBiz - CVE-2024-38856
Published: August 6, 2024 / Updated: February 12, 2025
OFBiz
Apache Foundation
Description
The vulnerability allows a remote attacker to execute arbitrary code on the system.
The vulnerability exists due to missing permission checks when accessing ProgramExport and EntitySQLProcessor endpoints. A remote attacker can send specially crafted requests to the affected endpoints and execute arbitrary code.