Create Apache OFbiz ProgramExport Command Execution Vulnerability(CVE-2024-38856).md

This commit is contained in:
Goby 2024-08-06 19:11:23 +08:00 committed by GitHub
parent 66d780b5ad
commit fb81d0502e
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194

View File

@ -0,0 +1,12 @@
**Updated document date: August 6, 2024**
## Apache OFbiz /ProgramExport Command Execution Vulnerability(CVE-2024-38856)
| **Vulnerability** | Apache OFbiz /ProgramExport Command Execution Vulnerability(CVE-2024-38856)|
| :----: | :-----|
| **Chinese name** | Apache OFbiz /ProgramExport 命令执行漏洞CVE-2024-38856 |
| **CVSS core** | 9.30 |
| **FOFA Query** (click to view the results directly)| [ app=“Apache_OFBiz”](https://fofa.info/result?qbase64=YXBwPSJBcGFjaGVfT0ZCaXoi)|
| **Number of assets affected** | 2,728 |
| **Description** |Apache OFBiz is an e-commerce platform used to build multi-layer and distributed e-commerce application systems at the enterprise level, cross-platform, cross-database, and cross-application servers. |
| **Impact** | Apache OFBiz has a logical flaw in handling the rendering of the view view, and an attacker can execute arbitrary code by constructing a special URL to override the final rendered view.
| **Affected versions** |Apache OFBiz <= 18.12.14