CVE-2024-38856
CRITICAL KEVApache OFBiz forgotPassword/ProgramExport RCE
Title source: metasploitDescription
Incorrect Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: through 18.12.14. Users are recommended to upgrade to version 18.12.15, which fixes the issue. Unauthenticated endpoints could allow execution of screen rendering code of screens if some preconditions are met (such as when the screen definitions don't explicitly check user's permissions because they rely on the configuration of their endpoints).
Exploits (14)
nomisec
WORKING POC
48 stars
by securelayer7 · remote
https://github.com/securelayer7/CVE-2024-38856_Scanner
nomisec
WORKING POC
3 stars
by Hex00-0x4 · remote
https://github.com/Hex00-0x4/CVE-2024-38856-Apache-OFBiz
nomisec
WORKING POC
1 stars
by FakesiteSecurity · remote
https://github.com/FakesiteSecurity/CVE-2024-38856_Scen
nomisec
WORKING POC
1 stars
by Praison001 · remote
https://github.com/Praison001/CVE-2024-38856-ApacheOfBiz
References (6)
Scores
CVSS v3
9.8
EPSS
0.9434
EPSS Percentile
100.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation Intel
CISA KEV
2024-08-27
VulnCheck KEV
2024-08-19
InTheWild.io
2024-08-27
ENISA EUVD
EUVD-2024-37643
Classification
CWE
CWE-863
Status
published
Affected Products (1)
apache/ofbiz
< 18.12.15
Timeline
Published
Aug 05, 2024
KEV Added
Aug 27, 2024
Tracked Since
Feb 18, 2026