Apache OFBiz Authentication Bypass Vulnerability (CVE-2023-49070 and CVE-2023-51467)

Поделиться
HTML-код
  • Опубликовано: 1 янв 2024
  • I created a PoC video about exploiting CVE-2023-51467 and CVE-2023-49070.
    The video serves demonstration purposes for a CVE analysis you can reach at www.vicarius.io/vsociety/.
    The Apache OFBiz Enterprise Resource Planning (ERP) system, a versatile Java-based web framework widely utilized across industries, is facing a critical security challenge. CVE-2023-51467 is a severe authentication bypass vulnerability with a CVSS score of 9.8 that not only exposes the ERP system to potential exploitation but also opens the door to a Server-Side Request Forgery (SSRF) exploit, presenting a dual threat to organizations relying on Apache OFBiz.
    Repo: github.com/jakabakos/Apache-OFBiz-Authentication-Bypass

Комментарии •