CVE-2015-6973

Ignite Realtime Openfire 3.10.2 - Cross-Site Request Forgery via Multiple Administrative Endpoints

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2015-6973. PoCs published by hyp3rlinx.

AI-analyzed exploit summary This exploit demonstrates CSRF vulnerabilities in Openfire 3.10.2, allowing unauthorized actions such as changing admin passwords, adding users, modifying server settings, and permitting malicious clients. The PoC includes HTML/JavaScript snippets and direct URLs to exploit these endpoints.

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in Ignite Realtime Openfire 3.10.2 allow remote attackers to hijack the authentication of administrators for requests that (1) change a password via a crafted request to user-password.jsp, (2) add users via a crafted request to user-create.jsp, (3) edit server settings or (4) disable SSL on the server via a crafted request to server-props.jsp, or (5) add clients via a crafted request to plugins/clientcontrol/permitted-clients.jsp.

Exploits (1)

exploitdb WORKING POC
by hyp3rlinx · textwebappsjsp
https://www.exploit-db.com/exploits/38192

This exploit demonstrates CSRF vulnerabilities in Openfire 3.10.2, allowing unauthorized actions such as changing admin passwords, adding users, modifying server settings, and permitting malicious clients. The PoC includes HTML/JavaScript snippets and direct URLs to exploit these endpoints.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Openfire 3.10.2
No auth needed
Prerequisites: Victim must be authenticated as an admin and visit a malicious page
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/536470/100/0/threaded
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/201612-50
Exploit exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/38192/

Scores

EPSS 0.6482
EPSS Percentile 99.1%

Details

CWE
CWE-352
Status published
Products (1)
igniterealtime/openfire 3.10.2
Published Sep 16, 2015
Tracked Since Feb 18, 2026