A vulnerability was found in OpenBoxes up to 0.9.2 and classified as critical. This vulnerability affects unknown code of the file grails-app/controllers/org/pih/warehouse/RoleInterceptor.groovy of the component Product Supplier Edit Controller. Executing a manipulation can lead to improper authorization.

This vulnerability appears as CVE-2024-14045. The attack may be performed from remote. In addition, an exploit is available.

It is suggested to upgrade the affected component.