PT-2025-31969 · Apache+1 · Apache Ofbiz+2

Jarukit Auikritskul

+1

·

Published

2025-08-05

·

Updated

2025-08-21

·

CVE-2025-54466

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Apache OFBiz versions prior to 24.09.02
Description: This issue involves improper control of code generation ('Code Injection') in the scrum plugin of Apache OFBiz, potentially leading to Remote Code Execution (RCE). Unauthenticated attackers can exploit this issue.
Recommendations: Upgrade to version 24.09.02.

Fix

RCE

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-54466

Affected Products

Apache Ofbiz
Ofbiz
Ofbiz-Framework