CVE-2023-51467
CRITICAL EXPLOITED NUCLEIApache OFBiz XML-RPC Java Deserialization
Title source: metasploitDescription
The vulnerability permits attackers to circumvent authentication processes, enabling them to remotely execute arbitrary code
Exploits (13)
nomisec
WORKING POC
72 stars
by jakabakos · poc
https://github.com/jakabakos/Apache-OFBiz-Authentication-Bypass
nomisec
SCANNER
11 stars
by K3ysTr0K3R · infoleak
https://github.com/K3ysTr0K3R/CVE-2023-51467-EXPLOIT
nomisec
WORKING POC
6 stars
by vulncheck-oss · remote
https://github.com/vulncheck-oss/cve-2023-51467
nomisec
NO CODE
by AhmedMansour93 · poc
https://github.com/AhmedMansour93/Event-ID-217-Rule-Name-SOC254-Apache-OFBiz-Auth-Bypass-and-Code-Injection-0Day-CVE-2023-51467-
vulncheck_xdb
WORKING POC
remote
https://github.com/Praison001/Apache-OFBiz-Auth-Bypass-and-RCE-Exploit-CVE-2023-49070-CVE-2023-51467
vulncheck_xdb
WORKING POC
infoleak
https://github.com/UserConnecting/Exploit-CVE-2023-49070-and-CVE-2023-51467-Apache-OFBiz
Nuclei Templates (1)
Apache OFBiz < 18.12.11 - Remote Code Execution
CRITICALby your3cho
Shodan:
html:"OFBiz" || http.html:"ofbiz" || ofbiz.visitor=
FOFA:
app="Apache_OFBiz" || body="ofbiz" || app="apache_ofbiz"
References (8)
Scores
CVSS v3
9.8
EPSS
0.9400
EPSS Percentile
99.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
VulnCheck KEV
2024-01-02
CWE
CWE-918
Status
published
Products (1)
apache/ofbiz
< 18.12.11
Published
Dec 26, 2023
Tracked Since
Feb 18, 2026