PT-2026-76908 · Openboxes · Openboxes
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
OpenBoxes versions prior to 0.9.3
Description
A remote manipulation of the Product Supplier Edit Controller within the file
grails-app/controllers/org/pih/warehouse/RoleInterceptor.groovy can lead to improper authorization.Recommendations
Upgrade to version 0.9.3.
Exploit
Fix
Incorrect Privilege Assignment
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openboxes