Vulnerabilities > Apache > Ofbiz > High

DATE CVE VULNERABILITY TITLE RISK
2017-08-30 CVE-2016-4462 Improper Input Validation vulnerability in Apache Ofbiz
By manipulating the URL parameter externalLoginKey, a malicious, logged in user could pass valid Freemarker directives to the Template Engine that are reflected on the webpage; a specially crafted Freemarker template could be used for remote code execution.
network
low complexity
apache CWE-20
8.8