Логотип exploitDog
bind:CVE-2017-15911
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2017-15911

Количество 2

Количество 2

nvd логотип

CVE-2017-15911

больше 8 лет назад

The Admin Console in Ignite Realtime Openfire Server before 4.1.7 allows arbitrary client-side JavaScript code execution on victims who click a crafted setup/setup-host-settings.jsp?domain= link, aka XSS. Session ID and data theft may follow as well as the possibility of bypassing CSRF protections, injection of iframes to establish communication channels, etc. The vulnerability is present after login into the application.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-v3h2-4j2r-wqj8

больше 3 лет назад

Ignite Realtime Openfire Server has Cross-site Scripting vulnerability in admin console

CVSS3: 4.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2017-15911

The Admin Console in Ignite Realtime Openfire Server before 4.1.7 allows arbitrary client-side JavaScript code execution on victims who click a crafted setup/setup-host-settings.jsp?domain= link, aka XSS. Session ID and data theft may follow as well as the possibility of bypassing CSRF protections, injection of iframes to establish communication channels, etc. The vulnerability is present after login into the application.

CVSS3: 4.8
0%
Низкий
больше 8 лет назад
github логотип
GHSA-v3h2-4j2r-wqj8

Ignite Realtime Openfire Server has Cross-site Scripting vulnerability in admin console

CVSS3: 4.8
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу