CVE-2025-54466
15.08.2025, 15:15
Improper Control of Generation of Code ('Code Injection') vulnerability leading to a possible RCE in Apache OFBizscrum plugin.
This issue affects Apache OFBiz: before 24.09.02 only when thescrum plugin is used.
Even unauthenticated attackers can exploit this vulnerability.
Users are recommended to upgrade to version 24.09.02, which fixes the issue.| Vendor | Product | Version |
|---|---|---|
| apache | ofbiz | 𝑥 < 24.09.02 |
𝑥
= Vulnerable software versions
References