What is CVE-2024-14045?
A vulnerability has been identified in OpenBoxes versions up to 0.9.2, affecting the Product Supplier Edit Controller component. The flaw exists in the 'RoleInterceptor.groovy' file and can lead to improper authorization upon manipulation. Users are advised to update to the latest version immediately.
Azərbaycanca: Bu zəiflik OpenBoxes proqramının 0.9.2 və aşağı versiyalarında aşkarlanıb. 'Product Supplier Edit Controller' komponentində yerləşən 'RoleInterceptor.groovy' faylındakı naməlum kod vasitəsilə düzgün olmayan səlahiyyət yoxlaması (improper authorization) baş verə bilər. İstifadəçilərə ən qısa zamanda ən son versiyaya yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of OpenBoxes are affected by the CVE-2024-14045 vulnerability?
This vulnerability has been identified in OpenBoxes versions up to 0.9.2.
In which component of OpenBoxes does the CVE-2024-14045 vulnerability exist?
The vulnerability exists in the 'Product Supplier Edit Controller' component, specifically in the 'RoleInterceptor.groovy' file.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.