cbcvebase.
CVE-2025-54466
published 2025-08-15

CVE-2025-54466: Improper Control of Generation of Code ('Code Injection') vulnerability leading to a possible RCE in Apache OFBiz scrum plugin. This issue affects Apache…

PriorityP271critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
14.95%
96.3th percentile
Improper Control of Generation of Code ('Code Injection') vulnerability leading to a possible RCE in Apache OFBiz scrum plugin. This issue affects Apache OFBiz: before 24.09.02 only when the scrum plugin is used. Even unauthenticated attackers can exploit this vulnerability. Users are recommended to upgrade to version 24.09.02, which fixes the issue.

Affected

3 ranges
VendorProductVersion rangeFixed in
apacheofbiz< 24.09.0224.09.02
apacheofbiz
apache_software_foundationapache_ofbiz< 24.09.0224.09.02

Detection & IOCsextracted from sources · hover to see the quote

versionApache OFBiz before 24.09.02 (scrum plugin)
  • Target unauthenticated attack surface: CVE-2025-54466 is exploitable without authentication against the Apache OFBiz scrum plugin — monitor for unexpected code execution or suspicious requests to scrum plugin endpoints from unauthenticated sessions.
  • Patch commit 5a35b4f84f in Apache OFBiz can be used as a reference to identify the vulnerable code path and craft detection logic around the affected scrum plugin functionality.
  • ·Vulnerability only applies when the scrum plugin is actively in use — installations without the scrum plugin are not affected.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_apache9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.