vendor:
Openfire
by:
SecurityFocus
7.5
CVSS
HIGH
Password Change Vulnerability
200
CWE
Product Name: Openfire
Affected Version From: Prior to 3.6.4
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: openfire
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
Openfire Password Change Vulnerability
Openfire is prone to a vulnerability that can permit an attacker to change the password of arbitrary users. Exploiting this issue can allow the attacker to gain unauthorized access to the affected application and to completely compromise victims' accounts.
Mitigation:
Upgrade to Openfire version 3.6.4 or later.