Description
By manipulating the URL parameter externalLoginKey, a malicious, logged in user could pass valid Freemarker directives to the Template Engine that are reflected on the webpage; a specially crafted Freemarker template could be used for remote code execution. Mitigation: Upgrade to Apache OFBiz 16.11.01
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2016-5451 | By manipulating the URL parameter externalLoginKey, a malicious, logged in user could pass valid Freemarker directives to the Template Engine that are reflected on the webpage; a specially crafted Freemarker template could be used for remote code execution. Mitigation: Upgrade to Apache OFBiz 16.11.01 |
References
| Link | Providers |
|---|---|
| http://git.net/ml/dev.ofbiz.apache.org/2016-11/msg00180.html |
|
History
No history.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-09-17T00:30:36.308Z
Reserved: 2016-05-02T00:00:00.000Z
Link: CVE-2016-4462
No data.
Status : Modified
Published: 2017-08-30T17:29:00.200
Modified: 2026-05-13T00:24:29.033
Link: CVE-2016-4462
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD