CVE-2025-54466
EUVD-2025-2502615.08.2025, 15:15
Improper Control of Generation of Code ('Code Injection') vulnerability leading to a possible RCE in Apache OFBiz scrum plugin.
This issue affects Apache OFBiz: before 24.09.02 only when the scrum plugin is used.
Even unauthenticated attackers can exploit this vulnerability.
Users are recommended to upgrade to version 24.09.02, which fixes the issue.Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| apache | ofbiz | 𝑥 < 24.09.02 |
𝑥
= Vulnerable software versions
References