vendor:
OpenFire
by:
hyp3rlinx
5,9
CVSS
MEDIUM
Reflected XSS
79
CWE
Product Name: OpenFire
Affected Version From: 3.10.2
Affected Version To: 4.0.1
Patch Exists: YES
Related CWE: CVE-2015-8252
CPE: a:igniterealtime:openfire
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2015-2016
Several vulnerabilities doscovered in OpenFire version 3.10.2 to 4.0.1
Several XSS vulnerabilities have been found on several pages of the administration panel. Reflected XSS may lead to session hijacking on admin user.
Mitigation:
The vendor released a patch for this vulnerability.