Pre-auth RCE in Apache Ofbiz 18.12.09. It's due to XML-RPC no longer maintained still present. This issue affects Apache OFBiz: before 18.12.10. Users are recommended to upgrade to version 18.12.10
PoC: Apache-OFBiz-Auth-Bypass-and-RCE-Exploit-CVE-2023-49070-CVE-2023-51467
This exploit scans whether the provided target is vulnerable to CVE-2023-49070/CVE-2023-51467 and also exploits it depending on the choice of the user.
PoC: CVE-2023-49070_CVE-2023-51467
CVE-2023-49070 exploit and CVE-2023-49070 & CVE-2023-51467 vulnerability scanner
PoC: Exploit-CVE-2023-49070-and-CVE-2023-51467-Apache-OFBiz
Authentication Bypass Vulnerability Apache OFBiz < 18.12.10.
PoC: OFBiz-Attack
A Tool For CVE-2023-49070/CVE-2023-51467 Attack
PoC: CVE-2023-49070
Pre-auth RCE in Apache Ofbiz!!
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free