CVE-2015-6973
Openfire 3.10.2 - Cross-Site Request Forgery
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Multiple cross-site request forgery (CSRF) vulnerabilities in Ignite Realtime Openfire 3.10.2 allow remote attackers to hijack the authentication of administrators for requests that (1) change a password via a crafted request to user-password.jsp, (2) add users via a crafted request to user-create.jsp, (3) edit server settings or (4) disable SSL on the server via a crafted request to server-props.jsp, or (5) add clients via a crafted request to plugins/clientcontrol/permitted-clients.jsp.
Múltiples vulnerabilidades de CSRF en Ignite Realtime Openfire 3.10.2 permiten a atacantes remotos secuestrar la autenticación de administradores para peticiones que (1) cambian una contraseña a través de una petición manipulada a user-password.jsp, (2) añaden usuarios a tavés de una petición manipulada a user-create.jsp, (3) editan ajustes de servidor o (4) desactivan SSL en el servidor a través de una petición a server-props.jsp manipulada o (5) añaden clientes a través de una petición manipulada a plugins/clientcontrol/permitted-clients.jsp.
Openfire version 3.10.2 suffers from a cross site request forgery vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-09-14 CVE Published
- 2015-09-16 CVE Reserved
- 2024-04-10 EPSS Updated
- 2024-08-06 CVE Updated
- 2024-08-06 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://hyp3rlinx.altervista.org/advisories/AS-OPENFIRE-CSRF.txt | X_refsource_misc | |
http://packetstormsecurity.com/files/133554/Openfire-3.10.2-Cross-Site-Request-Forgery.html | X_refsource_misc | |
http://www.securityfocus.com/archive/1/536470/100/0/threaded | Mailing List |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/38192 | 2024-08-06 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://security.gentoo.org/glsa/201612-50 | 2018-10-09 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Igniterealtime Search vendor "Igniterealtime" | Openfire Search vendor "Igniterealtime" for product "Openfire" | 3.10.2 Search vendor "Igniterealtime" for product "Openfire" and version "3.10.2" | - |
Affected
|