Description
Multiple cross-site scripting (XSS) vulnerabilities in Ignite Realtime Openfire 3.10.2 allow remote attackers to inject arbitrary web script or HTML via the (1) groupchatName parameter to plugins/clientcontrol/create-bookmark.jsp; the (2) urlName parameter to plugins/clientcontrol/create-bookmark.jsp; the (3) hostname parameter to server-session-details.jsp; or the (4) search parameter to group-summary.jsp.
Exploits (1)
References (4)
Core 4
Core References
Exploit x_refsource_misc
http://packetstormsecurity.com/files/133558/Openfire-3.10.2-Cross-Site-Scripting.html
Third Party Advisory vendor-advisory
x_refsource_gentoo
https://security.gentoo.org/glsa/201612-50
Exploit exploit
x_refsource_exploit-db
https://www.exploit-db.com/exploits/38191/
Various Sources x_refsource_misc
http://hyp3rlinx.altervista.org/advisories/AS-OPENFIRE-XSS.txt
Scores
EPSS
0.0456
EPSS Percentile
89.2%
Details
CWE
CWE-79
Status
published
Products (1)
igniterealtime/openfire
3.10.2
Published
Sep 16, 2015
Tracked Since
Feb 18, 2026