← Back to CVE List

CVE-2016-4462

Published: 2017-08-30T17:29Z
Last Modified: 2024-11-21T02:52Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
By manipulating the URL parameter externalLoginKey, a malicious, logged in user could pass valid Freemarker directives to the Template Engine that are reflected on the webpage; a specially crafted Freemarker template could be used for remote code execution. Mitigation: Upgrade to Apache OFBiz 16.11.01 > MITRE Terms of Use apply – see LICENSE‑MITRE.txt