PT-2026-41848 · Apache · Apache Ofbiz
Emily Bishop
+1
·
Published
2026-05-19
·
Updated
2026-05-19
·
CVE-2026-31379
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Apache OFBiz versions prior to 24.09.06
Description
Apache OFBiz contains issues involving improper neutralization of input during web page generation, improper limitation of a pathname to a restricted directory, and improper control of generation of code. These flaws allow for Cross-site Scripting (XSS), Path Traversal, and Code Injection, specifically within the Catalog Manager, which can lead to arbitrary file write, stored XSS, and Remote Code Execution (RCE).
Recommendations
Upgrade to version 24.09.06.
Fix
RCE
Path traversal
Code Injection
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Ofbiz