CVE-2024-38856
ID: f61ba052-00a2-5a65-b78c-1057c833ba2d
STIX ID: report--f61ba052-00a2-5a65-b78c-1057c833ba2d
Feed Name: Zscaler Security Research Blog
Threat Score
This report documents Apache OFBiz vulnerabilities CVE-2024-36104 and CVE-2024-38856 that allow remote command execution via the ProgramExport endpoint; notably, CVE-2024-38856 permits unauthenticated access when combined with any other unauthenticated endpoint (examples include forgotPassword, showDateTime, TestService, view, main), and the document provides proof-of-concept POST requests and attack-chain illustrations demonstrating successful command execution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
