Igniterealtime
Igniterealtime Openfire: vulnerabilidades y CVE
Igniterealtime Openfire tiene 38 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 3 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE38
Últimos 12 meses1
Críticas3
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-32315 | Alta (7.5) | 100% | ⚠ Explotación activa | 26 may 2023 | Openfire is an XMPP server licensed under the Open Source Apache License. Openfire's administrative console, a web-based application, was found to be vulnerable to a path traversal attack via the setup environment. This… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2020-36956 | Media (5.1) | 0.29% | — | 26 ene 2026 | Openfire 4.6.0 contains a stored cross-site scripting vulnerability in the nodejs plugin that allows attackers to inject malicious scripts through the 'path' parameter. Attackers can craft a payload with script tags to… |
| CVE-2024-25421 | Crítica (9.8) | 1.7% | — | 26 mar 2024 | An issue in Ignite Realtime Openfire v.4.9.0 and before allows a remote attacker to escalate privileges via the ROOM_CACHE component. |
| CVE-2024-25420 | Alta (7.2) | 1.4% | — | 26 mar 2024 | An issue in Ignite Realtime Openfire before 4.8.1 allows a remote attacker to escalate privileges via the admin.authorizedJIDs system property component. |
| CVE-2023-32315 | Alta (7.5) | 100% | ⚠ Explotación activa | 26 may 2023 | Openfire is an XMPP server licensed under the Open Source Apache License. Openfire's administrative console, a web-based application, was found to be vulnerable to a path traversal attack via the setup environment. This… |
| CVE-2021-45967 | Crítica (9.8) | 21% | — | 18 mar 2022 | An issue was discovered in Pascom Cloud Phone System before 7.20.x. A configuration error between NGINX and a backend Tomcat server leads to a path traversal in the Tomcat server, exposing unintended endpoints. |
| CVE-2020-35202 | Media (5.4) | 0.74% | — | 12 dic 2020 | Ignite Realtime Openfire 4.6.0 has plugins/dbaccess/db-access.jsp sql Stored XSS. |
| CVE-2020-35201 | Media (5.4) | 0.74% | — | 12 dic 2020 | Ignite Realtime Openfire 4.6.0 has create-bookmark.jsp users Stored XSS. |
| CVE-2020-35200 | Media (6.1) | 0.91% | — | 12 dic 2020 | Ignite Realtime Openfire 4.6.0 has plugins/clientcontrol/spark-form.jsp Reflective XSS. |
| CVE-2020-35199 | Media (5.4) | 0.62% | — | 12 dic 2020 | Ignite Realtime Openfire 4.6.0 has create-bookmark.jsp groupchatJID Stored XSS. |
| CVE-2020-35127 | Media (5.4) | 0.57% | — | 11 dic 2020 | Ignite Realtime Openfire 4.6.0 has plugins/bookmarks/create-bookmark.jsp Stored XSS. |
| CVE-2020-24604 | Media (6.1) | 1.2% | — | 2 sept 2020 | A Reflected XSS vulnerability was discovered in Ignite Realtime Openfire version 4.5.1. The XSS vulnerability allows remote attackers to inject arbitrary web script or HTML via the GET request "searchName",… |
| CVE-2020-24602 | Media (6.1) | 1.0% | — | 2 sept 2020 | Ignite Realtime Openfire 4.5.1 has a reflected Cross-site scripting vulnerability which allows an attacker to execute arbitrary malicious URL via the vulnerable GET parameter searchName", "searchValue",… |
| CVE-2020-24601 | Media (6.1) | 0.62% | — | 2 sept 2020 | In Ignite Realtime Openfire 4.5.1 a Stored Cross-site Vulnerability allows an attacker to execute an arbitrary malicious URL via the vulnerable POST parameter searchName", "alias" in the import certificate trusted page |
| CVE-2019-20526 | Media (6.1) | 0.91% | — | 19 mar 2020 | Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp password parameter. |
| CVE-2019-20525 | Media (6.1) | 0.91% | — | 19 mar 2020 | Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp driver parameter. |
| CVE-2019-20527 | Media (6.1) | 0.91% | — | 19 mar 2020 | Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp serverURL parameter. |
| CVE-2019-20528 | Media (6.1) | 0.91% | — | 18 mar 2020 | Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp username parameter. |
| CVE-2019-20366 | Media (6.1) | 1.3% | — | 8 ene 2020 | An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via isTrustStore to Manage Store Contents. |
| CVE-2019-20365 | Media (6.1) | 1.2% | — | 8 ene 2020 | An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via search to the Users/Group search page. |
| CVE-2019-20364 | Media (6.1) | 1.2% | — | 8 ene 2020 | An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via cacheName to SystemCacheDetails.jsp. |
| CVE-2019-20363 | Media (6.1) | 1.4% | — | 8 ene 2020 | An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via alias to Manage Store Contents. |
| CVE-2019-18394 | Crítica (9.8) | 32% | — | 24 oct 2019 | A Server Side Request Forgery (SSRF) vulnerability in FaviconServlet.java in Ignite Realtime Openfire through 4.4.2 allows attackers to send arbitrary HTTP GET requests. |
| CVE-2019-18393 | Media (5.3) | 14% | — | 24 oct 2019 | PluginServlet.java in Ignite Realtime Openfire through 4.4.2 does not ensure that retrieved files are located under the Openfire home directory, aka a directory traversal vulnerability. |
| CVE-2019-15488 | Media (6.1) | 0.91% | — | 23 ago 2019 | Ignite Realtime Openfire before 4.4.1 has reflected XSS via an LDAP setup test. |
| CVE-2018-11688 | Media (6.1) | 2.4% | — | 13 jun 2018 | Ignite Realtime Openfire before 3.9.2 is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability via a crafted URL to execute script… |
| CVE-2017-15911 | Media (4.8) | 0.73% | — | 26 oct 2017 | The Admin Console in Ignite Realtime Openfire Server before 4.1.7 allows arbitrary client-side JavaScript code execution on victims who click a crafted setup/setup-host-settings.jsp?domain= link, aka XSS. Session ID and… |
| CVE-2014-3451 | Alta (7.5) | 1.8% | — | 18 ago 2017 | OpenFire XMPP Server before 3.10 accepts self-signed certificates, which allows remote attackers to perform unspecified spoofing attacks. |
| CVE-2015-7707 | Media (6.5) | 6.0% | — | 5 oct 2015 | Ignite Realtime Openfire 3.10.2 allows remote authenticated users to gain administrator access via the isadmin parameter to user-edit-form.jsp. |
| CVE-2015-6973 | Media (6.8) | 65% | — | 16 sept 2015 | Multiple cross-site request forgery (CSRF) vulnerabilities in Ignite Realtime Openfire 3.10.2 allow remote attackers to hijack the authentication of administrators for requests that (1) change a password via a crafted… |
| CVE-2015-6972 | Media (4.3) | 8.0% | — | 16 sept 2015 | Multiple cross-site scripting (XSS) vulnerabilities in Ignite Realtime Openfire 3.10.2 allow remote attackers to inject arbitrary web script or HTML via the (1) groupchatName parameter to… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.