Home / exploitsPDF  

Apache OFBiz XML-RPC Java Deserialization

Posted on 12 March 2021

This Metasploit module exploits a Java deserialization vulnerability in Apache OFBiz's unauthenticated XML-RPC endpoint /webtools/control/xmlrpc for versions prior to 17.12.04.

 

TOP