Apache OFBiz 18.12.10, vulnerable to CVE-2023-51467: a request with `requirePasswordChange=Y` passes the authentication check, which reaches the webtools ProgramExport screen and runs Groovy code on the server.
Not startedDockercommit 04820cax86_64 · aarch64Secret
Exploit CVE-2023-51467 to bypass the login, run code on the OFBiz server and get a shell.
The brief for this lab lives in its repository.