cbcvebase.
CVE-2023-51467
published 2023-12-26

CVE-2023-51467: The vulnerability permits attackers to circumvent authentication processes, enabling them to remotely execute arbitrary code

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EXPLOIT
The vulnerability permits attackers to circumvent authentication processes, enabling them to remotely execute arbitrary code

Affected

3 ranges
VendorProductVersion rangeFixed in
apacheofbiz< 18.12.1118.12.11
apacheofbiz
apache_software_foundationapache_ofbiz< 18.12.1118.12.11

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL