Apache OFBiz XML-RPC Java Deserialization
Posted by deepcore on March 13, 2021 – 4:21 pm
This Metasploit module exploits a Java deserialization vulnerability in Apache OFBiz’s unauthenticated XML-RPC endpoint /webtools/control/xmlrpc for versions prior to 17.12.04.
Post a reply
You must be logged in to post a comment.