PT-2026-76908 · Openboxes · Openboxes

·

CVE-2024-14045

·

Published

2026-08-18

·

Updated

2026-08-18

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions OpenBoxes versions prior to 0.9.3
Description A remote manipulation of the Product Supplier Edit Controller within the file grails-app/controllers/org/pih/warehouse/RoleInterceptor.groovy can lead to improper authorization.
Recommendations Upgrade to version 0.9.3.

Exploit

Fix

Incorrect Privilege Assignment

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-14045

Affected Products

Openboxes