PT-2026-76911 · Openboxes · Openboxes

·

CVE-2024-14046

·

Published

2026-08-18

·

Updated

2026-08-18

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions OpenBoxes versions prior to 0.9.2
Description An unrestricted upload issue exists within the Document Upload Controller component. A remote attacker can exploit the DocumentController() function located in the grails-app/controllers/org/pih/warehouse/core/DocumentController.groovy file to upload files without proper restrictions.
Recommendations Update to version 0.9.2.

Exploit

Fix

Unrestricted File Upload

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-14046

Affected Products

Openboxes