Lucene search

K
githubexploit16F6F03E-DCFB-5B93-AFC4-08F524D903F8
HistoryDec 14, 2023 - 9:32 a.m.

Exploit for Code Injection in Apache Ofbiz

2023-12-1409:32:41
358
apache ofbiz
code injection
cve-2023-49070
pre-auth
rce
xml-rpc
java deserialization
ysoserial-all.jar
docker
image
marcopinball
demo

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

6.6 Medium

AI Score

Confidence

Low

0.798 High

EPSS

Percentile

98.3%

ofbiz-CVE-2023-49070-RCE-POC

This is a pre-auth RCE POC For C…

This is an article that belongs to githubexploit private collection.
Please sign in to get more Information.

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

6.6 Medium

AI Score

Confidence

Low

0.798 High

EPSS

Percentile

98.3%