CVE-2024-32113

CRITICAL KEV NUCLEI

Apache OFBiz <18.12.13 - Path Traversal

Title source: llm

Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before 18.12.13. Users are recommended to upgrade to version 18.12.13, which fixes the issue.

Exploits (8)

exploitdb WORKING POC
by Abdualhadi khalifa · textwebappsjava
https://www.exploit-db.com/exploits/52020
nomisec WORKING POC 27 stars
by Mr-xn · remote
https://github.com/Mr-xn/CVE-2024-32113
nomisec WORKING POC 8 stars
by RacerZ-fighting · poc
https://github.com/RacerZ-fighting/CVE-2024-32113-POC
nomisec WORKING POC 6 stars
by YongYe-Security · remote
https://github.com/YongYe-Security/CVE-2024-32113
nomisec WORKING POC
by luizgaf · remote
https://github.com/luizgaf/CVE-2024-32113-Exploit
nomisec WORKING POC
by guinea-offensive-security · remote
https://github.com/guinea-offensive-security/Ofbiz-RCE
metasploit WORKING POC EXCELLENT
by Mr-xn, jheysel-r7 · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/apache_ofbiz_forgot_password_directory_traversal.rb

Nuclei Templates (2)

Apache OFBiz Directory Traversal - Remote Code Execution
HIGHVERIFIEDby DhiyaneshDK
Shodan: title:"OFBiz"
FOFA: app="Apache_OFBiz"
Apache OFBiz - Improper Authorization & Remote Code Execution
CRITICALVERIFIEDby Co5mos
Shodan: title:"OFBiz"
FOFA: app="Apache_OFBiz"

Scores

CVSS v3 9.8
EPSS 0.9396
EPSS Percentile 99.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2024-08-07
VulnCheck KEV 2024-06-14
InTheWild.io 2024-08-07
ENISA EUVD EUVD-2024-29935
CWE
CWE-22
Status published
Products (1)
apache/ofbiz < 18.12.13
Published May 08, 2024
KEV Added Aug 07, 2024
Tracked Since Feb 18, 2026