Apache OFBiz XML-RPC Java Deserialization
Posted by deepcore on August 18, 2020 – 5:43 am
This Metasploit module exploits a Java deserialization vulnerability in Apache OFBiz’s unauthenticated XML-RPC endpoint /webtools/control/xmlrpc for versions prior to 17.12.04.
Post a reply
You must be logged in to post a comment.