Impact
A flaw in the buildZebraTemplate function of OpenBoxes’ DocumentController.groovy leads to improper neutralization of special elements in its template engine. The vulnerability is exposed through a remote template processing endpoint and has a publicly available exploit that can be initiated from the outside. The description notes that the issue may result in unintended processing of template elements, but it does not explicitly confirm arbitrary code execution.
Affected Systems
OpenBoxes releases version 0.9.6 and earlier are vulnerable. The fix is present in version 0.9.8‑hotfix1 and 0.9.8; upgrading to either of these resolves the problem.
Risk and Exploitability
The CVSS score of 5.3 indicates medium severity. No EPSS score is reported, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited documented exploitation. The attack vector is remote, and while an exploit exists publicly, its effectiveness depends on how the template processing endpoint is exposed. Organizations should consider the medium risk and remediated promptly.
OpenCVE Enrichment