CVE-2024-38856

CRITICAL KEV

Apache OFBiz forgotPassword/ProgramExport RCE

Title source: metasploit

Description

Incorrect Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: through 18.12.14. Users are recommended to upgrade to version 18.12.15, which fixes the issue. Unauthenticated endpoints could allow execution of screen rendering code of screens if some preconditions are met (such as when the screen definitions don't explicitly check user's permissions because they rely on the configuration of their endpoints).

Exploits (14)

nomisec WORKING POC 48 stars
by securelayer7 · remote
https://github.com/securelayer7/CVE-2024-38856_Scanner
nomisec WORKING POC 9 stars
by 0x20c · remote
https://github.com/0x20c/CVE-2024-38856-EXP
nomisec WORKING POC 3 stars
by Hex00-0x4 · remote
https://github.com/Hex00-0x4/CVE-2024-38856-Apache-OFBiz
nomisec STUB 3 stars
by BBD-YZZ · poc
https://github.com/BBD-YZZ/CVE-2024-38856-RCE
nomisec WORKING POC 2 stars
by ThatNotEasy · remote
https://github.com/ThatNotEasy/CVE-2024-38856
nomisec WORKING POC 1 stars
by FakesiteSecurity · remote
https://github.com/FakesiteSecurity/CVE-2024-38856_Scen
nomisec WORKING POC 1 stars
by Praison001 · remote
https://github.com/Praison001/CVE-2024-38856-ApacheOfBiz
nomisec SCANNER 1 stars
by emanueldosreis · remote
https://github.com/emanueldosreis/CVE-2024-38856
nomisec WORKING POC
by AlissonFaoli · remote
https://github.com/AlissonFaoli/Apache-OFBiz-Exploit
vulncheck_xdb WORKING POC
remote
https://github.com/GrassWorkshop/GrassWorkshop-practice-POC
vulncheck_xdb WORKING POC
remote
https://github.com/RacerZ-fighting/CVE-2024-32113-POC
vulncheck_xdb WORKING POC
remote
https://github.com/guinea-offensive-security/Ofbiz-RCE

Scores

CVSS v3 9.8
EPSS 0.9434
EPSS Percentile 100.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Exploitation Intel

CISA KEV 2024-08-27
VulnCheck KEV 2024-08-19
InTheWild.io 2024-08-27
ENISA EUVD EUVD-2024-37643

Classification

CWE
CWE-863
Status published

Affected Products (1)

apache/ofbiz < 18.12.15

Timeline

Published Aug 05, 2024
KEV Added Aug 27, 2024
Tracked Since Feb 18, 2026