CVE-2023-51467

CRITICAL EXPLOITED NUCLEI

Apache OFBiz XML-RPC Java Deserialization

Title source: metasploit

Description

The vulnerability permits attackers to circumvent authentication processes, enabling them to remotely execute arbitrary code

Exploits (13)

nomisec WORKING POC 72 stars
by jakabakos · poc
https://github.com/jakabakos/Apache-OFBiz-Authentication-Bypass
nomisec WORKING POC 39 stars
by ImuSpirit · poc
https://github.com/ImuSpirit/CVE-2023-51467-Exploit
nomisec SCANNER 11 stars
by K3ysTr0K3R · infoleak
https://github.com/K3ysTr0K3R/CVE-2023-51467-EXPLOIT
nomisec SCANNER 11 stars
by Chocapikk · infoleak
https://github.com/Chocapikk/CVE-2023-51467
nomisec WORKING POC 6 stars
by vulncheck-oss · remote
https://github.com/vulncheck-oss/cve-2023-51467
nomisec WORKING POC 4 stars
by ImuSpirit · remote
https://github.com/ImuSpirit/CVE-2023-51467
nomisec WORKING POC
by jakeotte · poc
https://github.com/jakeotte/BadBizness-CVE-2023-51467
nomisec SCANNER
by Subha-BOO7 · infoleak
https://github.com/Subha-BOO7/Exploit_CVE-2023-51467
vulncheck_xdb WORKING POC
remote
https://github.com/Praison001/Apache-OFBiz-Auth-Bypass-and-RCE-Exploit-CVE-2023-49070-CVE-2023-51467
vulncheck_xdb WORKING POC
remote
https://github.com/2ptr/BadBizness-CVE-2023-51467
vulncheck_xdb WORKING POC
remote
https://github.com/yukselberkay/CVE-2023-49070_CVE-2023-51467
vulncheck_xdb WORKING POC
infoleak
https://github.com/UserConnecting/Exploit-CVE-2023-49070-and-CVE-2023-51467-Apache-OFBiz

Nuclei Templates (1)

Apache OFBiz < 18.12.11 - Remote Code Execution
CRITICALby your3cho
Shodan: html:"OFBiz" || http.html:"ofbiz" || ofbiz.visitor=
FOFA: app="Apache_OFBiz" || body="ofbiz" || app="apache_ofbiz"

Scores

CVSS v3 9.8
EPSS 0.9400
EPSS Percentile 99.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2024-01-02
CWE
CWE-918
Status published
Products (1)
apache/ofbiz < 18.12.11
Published Dec 26, 2023
Tracked Since Feb 18, 2026