CVE-2023-49070
Pre-auth RCE in Apache Ofbiz 18.12.09. It's due to XML-RPC no longer maintained still present. This issue affects Apache OFBiz: before 18.12.10. Users are recommended to upgrade to version 18.12.10
- Affected products
- Apache Ofbiz
- Apache Ofbiz
- < 18.12.10
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 95.4% (100th percentile)
- Weakness
- CWE-94
- NVD status
- Modified
- Published
- 2023-12-05
CVE-2023-49070 at NVD
17 known exploits for CVE-2023-49070
Proof-of-concept code and exploit modules indexed by Sploitus
ofbiz-CVE-2023-49070-RCE-POC
Apache-OFBiz-Authentication-Bypass
Exploit-CVE-2023-49070-and-CVE-2023-51467-Apache-OFBiz
Apache-OFBiz-Auth-Bypass-and-RCE-Exploit-CVE-2023-49070-CVE-2023-51467
OFBiz-Attack
CVE-2023-49070_CVE-2023-51467
CVE-2023-49070
Exploit for Code Injection in Apache Ofbiz
Exploit for Server-Side Request Forgery in Apache Ofbiz
Exploit for Server-Side Request Forgery in Apache Ofbiz
Exploit for Code Injection in Apache Ofbiz
Exploit for Code Injection in Apache Ofbiz
Apache OFBiz 18.12.09 Remote Code Execution
Exploit for Server-Side Request Forgery in Apache Ofbiz
Apache OFBiz 18.12.09 Remote Code Execution Exploit
Exploit for Code Injection in Apache Ofbiz
Exploit for Code Injection in Apache Ofbiz