OpenFire 3.10.2 < 4.0.1 -...

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

# Several vulnerabilities doscovered in OpenFire version 3.10.2 to 4.0.1 ## Product Description **OpenFire** is an opensource project under GNU GPL licence. It provides a Jabber/XMPP server fully develloped in Java. It's develloped by the **Ignite realtime** community. The actual version of the product is 4.0.2. Official web site : http://igniterealtime.org/ Several vulnerabilities have been discovered between 2015, October and 2016, February. Reported vulnerabilities are similar to those previously discovered by hyp3rlinx, although they concern different pages. In brief, the flaws are of the following kinds: CSRF, XSS (reflected and stored), file upload and information disclosure. Most vulnerabilities need an administration access to the web application and may lead to personal information leakage or account take-over. **Ingnite realtime** fixed some vulnerabilities (the corresponding commit ID are indicated in this document). ## Several Relected XSS Vulnerabilities identified in...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息