CVE-2020-9496
MEDIUM 6.1EPSS 98.9%
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
- CVSS v3.1
- 6.1 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N - CVSS v2.0
- 4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N - EPSS
- 98.93% chance of exploitation in the next 30 days, 100th percentile
- Nuclei
- medium · CWE-502
- Published
- 2020-07-15
- Updated
- 2024-08-04
Proof-of-concept exploits (12)
- http://packetstormsecurity.com/files/158887/Apache-OFBiz-XML-RPC-Java-Deserialization.html
- http://packetstormsecurity.com/files/161769/Apache-OFBiz-XML-RPC-Java-Deserialization.html
- http://packetstormsecurity.com/files/163730/Apache-OfBiz-17.12.01-Remote-Command-Executio…
- JulianWu520/DriedMango8★ · 2021-07-12
- Ly0nt4r/CVE-2020-94962★ · 2023-04-23
- MrMeizhi/DriedMango8★ · 2021-07-12
- Vulnmachines/apache-ofbiz-CVE-2020-94961★ · 2021-06-10
- ambalabanov/CVE-2020-94960★ · 2021-06-06
- cyber-niz/CVE-2020-94960★ · 2021-05-07
- dwisiswant0/CVE-2020-94963★ · 2020-08-16
- g33xter/CVE-2020-94967★ · 2021-04-30
- s4dbrd/CVE-2020-94964★ · 2021-08-04
Nuclei templates (1)
Metasploit modules (1)
ExploitDB entries (1)
Vulhub environments (1)
Exploit collections (2)
- chaitin/xray/blob/master/pocs/apache-ofbiz-cve-2020-9496-xml-deserialization.yml
- zan8in/afrog/blob/main/pocs/afrog-pocs/CVE/2020/CVE-2020-9496.yaml