No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 16 Aug 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was found in OpenBoxes up to 0.9.7. The impacted element is the function Upload of the file grails-app/controllers/org/pih/warehouse/product/ProductController.groovy of the component Product Upload Endpoint. Performing a manipulation of the argument params.url results in server-side request forgery. The attack is possible to be carried out remotely. The exploit has been made public and could be used. Upgrading to version 0.9.8-hotfix1 and 0.9.8 is sufficient to resolve this issue. The patch is named a599007325efe780a21b3537ecce3ca25635c926. It is suggested to upgrade the affected component. | |
| Title | OpenBoxes Product Upload Endpoint ProductController.groovy upload server-side request forgery | |
| First Time appeared |
Openboxes
Openboxes openboxes |
|
| Weaknesses | CWE-918 | |
| CPEs | cpe:2.3:a:openboxes:openboxes:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Openboxes
Openboxes openboxes |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-08-16T02:00:14.639Z
Reserved: 2026-08-15T05:46:46.432Z
Link: CVE-2026-19927
No data.
Status : Received
Published: 2026-08-16T03:16:49.333
Modified: 2026-08-16T03:16:49.333
Link: CVE-2026-19927
No data.
OpenCVE Enrichment
No data.
-
CWE-918
Server-Side Request Forgery (SSRF)