QID 730213
Date Published: 2021-09-30
QID 730213: Openfire Cross-Site Scripting (XSS) Vulnerability (OF-1019)
Openfire is a Jabber server supported by Ignite Realtime. It is a cross-platform Java application, which positions itself as a platform for medium-sized enterprises to control internal communications and make instant messaging easier.
CVE-2015-6972: Multiple cross-site scripting (XSS) vulnerabilities in Ignite Realtime Openfire 3.10.2 allow remote attackers to inject arbitrary web script or HTML via the (1) groupchatName parameter to plugins/clientcontrol/create-bookmark.jsp; the (2) urlName parameter to plugins/clientcontrol/create-bookmark.jsp; the (3) hostname parameter to server-session-details.jsp; or the (4) search parameter to group-summary.jsp.
Affected Products:
Openfire version 3.10.2
QID Detection Logic:(Unauthenticated)
It checks for vulnerable version of Openfire.
Successful exploitation of this vulnerability may allow an attacker to steal admin session using XSS.
CVEs related to QID 730213
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| OF-1019 |
|