Home / os / wince

Apache OFBiz Forgot Password Directory Traversal

Posted on 18 June 2024

Apache OFBiz versions prior to 18.12.13 are vulnerable to a path traversal vulnerability. The vulnerable endpoint /webtools/control/forgotPassword allows an attacker to access the ProgramExport endpoint which in turn allows for remote code execution in the context of the user running the application.

 

TOP