PT-2017-14280 · Ignite Realtime · Openfire Server

Published

2017-10-26

·

Updated

2022-05-17

·

CVE-2017-15911

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Openfire Server versions prior to 4.1.7
Description The issue allows arbitrary client-side JavaScript code execution on victims who click a crafted setup/setup-host-settings.jsp?domain= link. This can lead to session ID and data theft, bypassing CSRF protections, injection of iframes to establish communication channels, and other potential attacks.
Recommendations For versions prior to 4.1.7, update to version 4.1.7 or later to resolve the issue. As a temporary workaround, consider restricting access to the setup-host-settings.jsp page until the update is applied. Avoid clicking on suspicious links, especially those with crafted domain parameters, to minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-15911
GHSA-V3H2-4J2R-WQJ8

Affected Products

Openfire Server