vendor:
Openfire
by:
Vendor Contacted
7.5
CVSS
HIGH
Multiple CSRF
352
CWE
Product Name: Openfire
Affected Version From: 3.6.2004
Affected Version To: 3.6.2004
Patch Exists: NO
Related CWE: N/A
CPE: a:igniterealtime:openfire
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010
Multiple CSRF Vulnerabilities in Openfire 3.6.4 Administrative Section
Multiple CSRF vulnerabilities were discovered in Openfire 3.6.4 Administrative Section. The vulnerable pages are user-create.jsp, user-password.jsp, user-delete.jsp, group-create.jsp, and group-edit.jsp. An attacker could exploit these vulnerabilities to perform malicious actions on behalf of the user.
Mitigation:
No fixes are available for these vulnerabilities.