Jacques Le Roux created OFBIZ-11948:
---------------------------------------
Summary: Remote Code Execution (File Upload) Vulnerability
Key: OFBIZ-11948
URL:
https://issues.apache.org/jira/browse/OFBIZ-11948 Project: OFBiz
Issue Type: Sub-task
Reporter: Jacques Le Roux
Harshit Shukla
[hidden email] this RCE vulnerability to the OFBiz security team, and we thank him for that.
I'll later quote here his email message when the vulnerability will be fixed. It's a post-auth vulnerability so we did not ask for a CVE.
--
This message was sent by Atlassian Jira
(v8.3.4#803005)