CVE-2023-51467
Apache OFBiz: Pre-authentication Remote Code Execution (RCE) vulnerability
- Published
- Dec 26, 2023
- Updated
- Aug 19, 2024
- Assigning CNA
- apache
- Evidence observed
- Aug 8, 2026
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HHigh · next 30 days
- Percentile
- 99.9%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
The vulnerability permits attackers to circumvent authentication processes, enabling them to remotely execute arbitrary code
Sources
10This exploit scans whether the provided target is vulnerable to CVE-2023-49070/CVE-2023-51467 and also exploits it depending on the choice of the user.
- cve-2023-51467Exploit
A go-exploit for Apache OFBiz CVE-2023-51467
Exploit and vulnerability scanner for CVE-2023-49070 and CVE-2023-51467, enabling automated detection and exploitation of Apache OFBiz vulnerabilities.
This repo is a PoC with to exploit CVE-2023-51467 and CVE-2023-49070 preauth RCE vulnerabilities found in Apache OFBiz.
- OFBiz-AttackExploit
A Tool For CVE-2023-49070/CVE-2023-51467 Attack
CVE-2023-51467 POC
- BadBizness-CVE-2023-51467Exploit
Auto exploit script for the Java web framework OF Biz under CVE-2023-51467.
A PoC exploit for CVE-2023-51467 - Apache OFBiz Authentication Bypass
Exploit for CVE-2023-51467, a web application vulnerability, providing proof-of-concept code for security testing and validation.
Authentication Bypass Vulnerability Apache OFBiz < 18.12.10.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.