Cross-site Scripting and Path Traversal Vulnerabilities in Apache OFBiz
CVE-2026-31379
6.1MEDIUM
What is CVE-2026-31379?
Apache OFBiz is subject to multiple vulnerabilities that compromise web application security, including cross-site scripting (XSS), path traversal, and code injection issues. The improper handling of user inputs could allow malicious actors to execute arbitrary scripts in the context of the affected users, access restricted directories, or manipulate the executed code. Users are advised to upgrade to version 24.09.06 to mitigate these security risks.
Affected Version(s)
Apache OFBiz 0 < 24.09.06
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Sho Odagiri of GMO Cybersecurity by Ierae, Inc.
Emily Bishop of 992labs