vendor:
Openfire
by:
hyp3rlinx
8,8
CVSS
HIGH
Cross site request forgery (CSRF)
352
CWE
Product Name: Openfire
Affected Version From: 3.10.2
Affected Version To: 3.10.2
Patch Exists: YES
Related CWE: N/A
CPE: a:igniterealtime:openfire:3.10.2
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2014
Openfire 3.10.2 Cross site request forgery (CSRF)
No CSRF tokens exists allowing us to take malicious actions against the application. 1- change admin password. 2- add aribitrary users to the system 3- edit server settings e.g. turn off SSL. 4- Add rogue malicious clients with permit access (Allow all XMPP clients to connect) and more...
Mitigation:
Upgrade to the latest version of Openfire.