2021-05-18 14:14:09 +08:00
..
2021-05-18 14:14:09 +08:00
2021-05-18 14:14:09 +08:00

CVE-2021-30128 Apache OFBiz RCE

Apache OFBiz has unsafe deserialization prior to 17.12.06. An unauthenticated attacker can use this vulnerability to successfully take over Apache OFBiz.

Affected version: Apache OFBiz 17.12.06

FOFA query rule: header="Set-Cookie: OFBiz.Visitor"

Demo