Description: | | Apache OFBiz is an Enterprise Resource Planning (ERP) system developed by the Apache Software Foundation. This system provides a comprehensive set of Java-based web application components and tools. Prior to version 18.12.10 of Apache OFBiz, there exists a code injection vulnerability. This vulnerability originates from an incomplete fix for the associated CVE-2020-9496 vulnerability in its XML-RPC component. It allows attackers to re-exploit the vulnerability by bypassing permissions. Currently, XML-RPC is no longer maintained, and Apache OFBiz has removed XML-RPC in its latest release, version 18.12.10. However, earlier versions may still be susceptible to this vulnerability. |