PT-2026-73073 · Openboxes · Openboxes

·

CVE-2026-19927

·

Published

2026-08-16

·

Updated

2026-08-17

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions OpenBoxes versions prior to 0.9.8-hotfix1
Description A server-side request forgery (SSRF) exists in the Product Upload Endpoint. A remote attacker can manipulate the params.url variable within the Upload() function of the file grails-app/controllers/org/pih/warehouse/product/ProductController.groovy to trigger the issue. SSRF is a flaw that allows an attacker to induce the server-side application to make requests to an unintended location.
Recommendations Upgrade to version 0.9.8-hotfix1 or 0.9.8. As a temporary mitigation, restrict access to the Upload() function in the Product Upload Endpoint.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19927
GHSA-828R-3VX8-65WX

Affected Products

Openboxes