CVE-2024-32113
CRITICAL KEV NUCLEIApache OFBiz <18.12.13 - Path Traversal
Title source: llmDescription
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before 18.12.13. Users are recommended to upgrade to version 18.12.13, which fixes the issue.
Exploits (8)
exploitdb
WORKING POC
by Abdualhadi khalifa · textwebappsjava
https://www.exploit-db.com/exploits/52020
nomisec
WORKING POC
8 stars
by RacerZ-fighting · poc
https://github.com/RacerZ-fighting/CVE-2024-32113-POC
nomisec
WORKING POC
6 stars
by YongYe-Security · remote
https://github.com/YongYe-Security/CVE-2024-32113
nomisec
WORKING POC
by guinea-offensive-security · remote
https://github.com/guinea-offensive-security/Ofbiz-RCE
metasploit
WORKING POC
EXCELLENT
by Mr-xn, jheysel-r7 · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/apache_ofbiz_forgot_password_directory_traversal.rb
Nuclei Templates (2)
Apache OFBiz Directory Traversal - Remote Code Execution
HIGHVERIFIEDby DhiyaneshDK
Shodan:
title:"OFBiz"
FOFA:
app="Apache_OFBiz"
Apache OFBiz - Improper Authorization & Remote Code Execution
CRITICALVERIFIEDby Co5mos
Shodan:
title:"OFBiz"
FOFA:
app="Apache_OFBiz"
References (6)
Scores
CVSS v3
9.8
EPSS
0.9396
EPSS Percentile
99.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CISA KEV
2024-08-07
VulnCheck KEV
2024-06-14
InTheWild.io
2024-08-07
ENISA EUVD
EUVD-2024-29935
CWE
CWE-22
Status
published
Products (1)
apache/ofbiz
< 18.12.13
Published
May 08, 2024
KEV Added
Aug 07, 2024
Tracked Since
Feb 18, 2026