Code Injection Vulnerability in Apache OFBiz Scrum Plugin
CVE-2025-54466

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
15 August 2025

What is CVE-2025-54466?

A code injection vulnerability in the Apache OFBiz scrum plugin can lead to remote code execution (RCE) by unauthenticated attackers. This issue affects versions of Apache OFBiz prior to 24.09.02, making it critical for users of the scrum plugin to update to the latest version to protect their systems against potential exploitation.

Affected Version(s)

Apache OFBiz 0 < 24.09.02

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Teeramet Eakwilai <[email protected]>
Thanasin Luangpipat
Jarukit Auikritskul
.
CVE-2025-54466 : Code Injection Vulnerability in Apache OFBiz Scrum Plugin