SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2024-14045

MEDIUM · CVSS 6.3 EPSS 0.24% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-18 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A vulnerability in OpenBoxes versions up to 0.9.2 allows for improper authorization through manipulation of the Product Supplier Edit Controller, potentially enabling remote attacks. Organizations using this software should prioritize upgrading to version 0.9.3, which addresses the issue, to mitigate the risk of exploitation. Given the public availability of the exploit, immediate action is recommended for all users of the affected component.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2024-14045
Severity
MEDIUM
CVSS
6.3
EPSS
0.24%

Original NVD Description

A weakness has been identified in OpenBoxes up to 0.9.2. This vulnerability affects unknown code of the file grails-app/controllers/org/pih/warehouse/RoleInterceptor.groovy of the component Product Supplier Edit Controller. Executing a manipulation can lead to improper authorization. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. Upgrading to version 0.9.3 is able to resolve this issue. This patch is called f767ac1a5987d4865d9f158c6a967680f8e45468. It is suggested to upgrade the affected component.