Exploitation Summary
EIP tracks 1 public exploit for CVE-2019-0235. PoCs published by Faiz Ahmed Zaidi.
AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in Apache OFBiz versions before 17.12.03, allowing an attacker to change the admin's email address via a crafted HTML form. The attacker can then reset the password to take over the account.
Description
Apache OFBiz 17.12.01 is vulnerable to some CSRF attacks.
Exploits (1)
exploitdb
WORKING POC
by Faiz Ahmed Zaidi · textwebappsjava
https://www.exploit-db.com/exploits/48408
This exploit demonstrates a CSRF vulnerability in Apache OFBiz versions before 17.12.03, allowing an attacker to change the admin's email address via a crafted HTML form. The attacker can then reset the password to take over the account.
Classification
Working Poc 100%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target:
Apache OFBiz < 17.12.03
No auth needed
Prerequisites:
Victim must visit the malicious HTML page · Target must be logged into OFBiz as admin
devstral-2 · analyzed Feb 16, 2026
Full analysis →
References (9)
Core 9
Core References
Mailing List, Vendor Advisory x_refsource_confirm
https://s.apache.org/n4vnt
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
http://packetstormsecurity.com/files/157514/Apache-OFBiz-17.12.03-Cross-Site-Request-Forgery.html
Mailing List mailing-list
x_refsource_mlist
https://lists.apache.org/thread.html/rbd572bb27991835a3455c1bf694e7140d79ab03cdb9e6e50fd1219d7%40%3Cnotifications.ofbiz.apache.org%3E
Mailing List mailing-list
x_refsource_mlist
https://lists.apache.org/thread.html/r392206f7cd131f0fc3f7c60a767ced93ced00411d55c1777c219c956%40%3Cnotifications.ofbiz.apache.org%3E
Mailing List mailing-list
x_refsource_mlist
https://lists.apache.org/thread.html/rfe36dc9135810954ef667d29129d02207fb999a286b60d33bd9c2349%40%3Cnotifications.ofbiz.apache.org%3E
Mailing List mailing-list
x_refsource_mlist
https://lists.apache.org/thread.html/r9eeb6c41d2c562b451f1e48ec56881f59107cc4dea7c883db2c5373d%40%3Cnotifications.ofbiz.apache.org%3E
Mailing List mailing-list
x_refsource_mlist
https://lists.apache.org/thread.html/rb53870d24088956a555683aa1aea7e532e3be65b863b9c75eac31b90%40%3Ccommits.ofbiz.apache.org%3E
Mailing List mailing-list
x_refsource_mlist
https://lists.apache.org/thread.html/r90890afea72a9571d666820b2fe5942a0a5f86be406fa31da3dd0922%40%3Cannounce.apache.org%3E
Mailing List mailing-list
x_refsource_mlist
https://lists.apache.org/thread.html/r1125f3044a0946d1e7e6f125a6170b58d413ebd4a95157e4608041c7%40%3Cannounce.apache.org%3E
Scores
CVSS v3
8.8
EPSS
0.3275
EPSS Percentile
98.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Details
CWE
CWE-352
Status
published
Products (1)
apache/ofbiz
17.12.01
Published
Apr 30, 2020
Tracked Since
Feb 18, 2026