A vulnerability was found in OpenBoxes up to 0.9.1. It has been classified as critical. This issue affects the function
DocumentController of the file grails-app/controllers/org/pih/warehouse/core/DocumentController.groovy of the component Document Upload Controller. The manipulation leads to unrestricted upload.
This vulnerability is traded as CVE-2024-14046. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
Upgrading the affected component is recommended.