KEVIntel
9.8
CVSS
Critical

CVE-2023-51467

PUBLISHED

Apache OFBiz: Pre-authentication Remote Code Execution (RCE) vulnerability

Not yet in CISA KEV

Exploited in the wild PoC available Remote Low complexity No user interaction
Vendor
Apache Software Foundation
Product
Apache OFBiz
Published
Dec 26, 2023
EPSS

Automate This Intelligence with the Pro API

Everything on this page — CVSS, EPSS, exploit status, PoCs, scanner integrations, mentions, tags, and immediate honeypot data — is available programmatically for VM, SOC, and CTI workflows.

Description

The vulnerability permits attackers to circumvent authentication processes, enabling them to remotely execute arbitrary code

nuclei_scanner

CVSS Scores

CVSS v3.1 9.8 Critical

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Exploitation Status

Exploited in the wild

Recorded 2026-06-08 00:00:00 UTC · The Shadowserver (via CIRCL)

Proof of concept available

Recorded 2023-12-29 15:01:46 UTC · GitHub

Known Exploited Vulnerability Sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
The Shadowserver (via CIRCL) First 2025-06-30 00:00 UTC

Potential Proof of Concepts

These PoCs are unverified and could contain malware. Use at your own risk.

ImuSpirit/CVE-2023-51467-Exploit

github · Created 2024-01-06 04:07:07 UTC · 38 stars

Apache Ofbiz CVE-2023-51467 图形化漏洞利用工具

K3ysTr0K3R/CVE-2023-51467-EXPLOIT

github · Created 2023-12-29 17:47:54 UTC · 11 stars

A PoC exploit for CVE-2023-51467 - Apache OFBiz Authentication Bypass

Chocapikk/CVE-2023-51467

github · Created 2023-12-29 15:01:46 UTC · 11 stars

Apache OfBiz Auth Bypass Scanner for CVE-2023-51467

ImuSpirit/CVE-2023-51467

github · Created 2023-12-29 02:25:43 UTC · 4 stars

CVE-2023-51467 POC

CVE-2023-51467

nuclei · Created Unknown

apache_ofbiz_deserialization

metasploit · Created Unknown

Metasploit module for CVE-2023-51467

Timeline

  • Added to KEVIntel

  • Detected by Metasploit

  • Detected by Nuclei

  • Proof of Concept Exploit Available

  • CVE Published to Public

  • CVE ID Reserved