Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2023-51467— Apache OFBiz: Pre-authentication Remote Code Execution (RCE) vulnerability

EPSS 94.00% · P100
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2023-51467

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Apache OFBiz: Pre-authentication Remote Code Execution (RCE) vulnerability
Source: NVD (National Vulnerability Database)
Vulnerability Description
The vulnerability permits attackers to circumvent authentication processes, enabling them to remotely execute arbitrary code
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Apache OFBiz 代码问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Apache OFBiz是美国阿帕奇(Apache)基金会的一套企业资源计划(ERP)系统。该系统提供了一整套基于Java的Web应用程序组件和工具。 Apache OFBiz 18.12.11之前版本存在代码问题漏洞,该漏洞源于允许攻击者绕过身份验证来实现服务器端请求伪造。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
Apache Software FoundationApache OFBiz 0 ~ 18.12.11 -

II. Public POCs for CVE-2023-51467

#POC DescriptionSource LinkShenlong Link
1CVE-2023-51467 POChttps://github.com/JaneMandy/CVE-2023-51467POC Details
2Apache OfBiz Auth Bypass Scanner for CVE-2023-51467https://github.com/Chocapikk/CVE-2023-51467POC Details
3Nonehttps://github.com/K3ysTr0K3R/CVE-2023-51467-EXPLOITPOC Details
4This repo is a PoC with to exploit CVE-2023-51467 and CVE-2023-49070 preauth RCE vulnerabilities found in Apache OFBiz.https://github.com/jakabakos/Apache-OFBiz-Authentication-BypassPOC Details
5Nonehttps://github.com/Subha-BOO7/Exploit_CVE-2023-51467POC Details
6Apache Ofbiz CVE-2023-51467 图形化漏洞利用工具https://github.com/JaneMandy/CVE-2023-51467-ExploitPOC Details
7A go-exploit for Apache OFBiz CVE-2023-51467https://github.com/vulncheck-oss/cve-2023-51467POC Details
8Auto exploit script for the Java web framework OF Biz under CVE-2023-51467. https://github.com/Jake123otte1/BadBiznessPOC Details
9Auto exploit script for the Java web framework OF Biz under CVE-2023-51467. https://github.com/Jake123otte1/BadBizness-CVE-2023-51467POC Details
10Apache OFBiz Authentication Bypass Vulnerability (CVE-2023-51467 and CVE-2023-49070)https://github.com/pulentoski/CVE-2023-51467-and-CVE-2023-49070POC Details
11Auto exploit script for the Java web framework OF Biz under CVE-2023-51467. https://github.com/tw0point/BadBizness-CVE-2023-51467POC Details
12🚨 Just completed an incident report on Event ID 217: Apache OFBiz Auth Bypass and Code Injection 0-Day (CVE-2023-51467). This critical vulnerability allows attackers to bypass authentication and execute code remotely! Stay vigilant and ensure your systems are patched! Big thanks to LetsDefend.io for the platform to practice real-world scenarios.https://github.com/AhmedMansour93/Event-ID-217-Rule-Name-SOC254-Apache-OFBiz-Auth-Bypass-and-Code-Injection-0Day-CVE-2023-51467-POC Details
13Auto exploit script for the Java web framework OF Biz under CVE-2023-51467. https://github.com/2ptr/BadBizness-CVE-2023-51467POC Details
14The vulnerability allows attackers to bypass authentication to achieve a simple Server-Side Request Forgery (SSRF) https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-51467.yamlPOC Details
15Nonehttps://github.com/Threekiii/Awesome-POC/blob/master/%E5%BC%80%E5%8F%91%E6%A1%86%E6%9E%B6%E6%BC%8F%E6%B4%9E/Apache%20OfBiz%20%E9%89%B4%E6%9D%83%E7%BB%95%E8%BF%87%E5%AF%BC%E8%87%B4%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%20CVE-2023-51467.mdPOC Details
16https://github.com/vulhub/vulhub/blob/master/ofbiz/CVE-2023-51467/README.mdPOC Details
17CVE-2023-51467 POChttps://github.com/ImuSpirit/CVE-2023-51467POC Details
18Apache Ofbiz CVE-2023-51467 图形化漏洞利用工具https://github.com/ImuSpirit/CVE-2023-51467-ExploitPOC Details
19Auto exploit script for the Java web framework OF Biz under CVE-2023-51467. https://github.com/jakeotte/BadBizness-CVE-2023-51467POC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-51467

登录查看更多情报信息。

IV. Related Vulnerabilities

V. Comments for CVE-2023-51467

No comments yet


Leave a comment