vendor:
OFBiz
by:
Abdualhadi Khalifa
6.1
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: OFBiz
Affected Version From: 18.12.12
Affected Version To: 18.12.12
Patch Exists: NO
Related CWE:
CPE: a:apache:ofbiz
Platforms Tested: Windows
2024
Apache OFBiz 18.12.12 – Directory Traversal
Apache OFBiz version 18.12.12 and below is vulnerable to directory traversal. An attacker can exploit this vulnerability by sending a crafted XML request to the '/webtools/control/xmlrpc' endpoint, allowing them to access files outside of the web root directory, such as sensitive system files like '/etc/passwd' or executing commands on the server.
Mitigation:
To mitigate this vulnerability, it is recommended to update Apache OFBiz to a version above 18.12.12 and restrict access to the '/webtools/control/xmlrpc' endpoint if not needed.