CVE-2019-18393

MEDIUM EXPLOITED NUCLEI

Openfire < 4.4.2 - Path Traversal via PluginServlet.java

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2019-18393 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 2 public exploits from researchers including dawetmaster, andikahilmy. A Nuclei detection template is also available.

AI-analyzed exploit summary This repository appears to be a fork or clone of the Openfire project itself, not an exploit PoC. It contains build scripts, Dockerfiles, and source code for Openfire but lacks any exploit code or technical analysis related to CVE-2019-18393.

Description

PluginServlet.java in Ignite Realtime Openfire through 4.4.2 does not ensure that retrieved files are located under the Openfire home directory, aka a directory traversal vulnerability.

Exploits (2)

nomisec STUB
by dawetmaster · poc
https://github.com/dawetmaster/CVE-2019-18393-Openfire-vulnerable

This repository appears to be a fork or clone of the Openfire project itself, not an exploit PoC. It contains build scripts, Dockerfiles, and source code for Openfire but lacks any exploit code or technical analysis related to CVE-2019-18393.

Classification
Stub 90%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: Openfire (version not specified)
No auth needed
Prerequisites: None identified
devstral-2 · analyzed Mar 14, 2026 Full analysis →
nomisec STUB
by andikahilmy · poc
https://github.com/andikahilmy/CVE-2019-18393-Openfire-vulnerable

This repository appears to be a fork or clone of the Openfire project itself, not an exploit PoC. It contains build scripts, Dockerfiles, and source code for Openfire but lacks any exploit code or technical analysis related to CVE-2019-18393.

Classification
Stub 90%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: Openfire (version not specified)
No auth needed
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Nuclei Templates (1)

Ignite Realtime Openfire <4.42 - Local File Inclusion
MEDIUMby pikpikcu
Shodan: http.title:"openfire admin console" || http.title:"openfire"
FOFA: title="openfire" || title="openfire admin console"

References (2)

Core 2
Core References
Patch, Third Party Advisory x_refsource_misc
https://github.com/igniterealtime/Openfire/pull/1498
Various Sources x_refsource_misc
https://swarm.ptsecurity.com/openfire-admin-console/

Scores

CVSS v3 5.3
EPSS 0.8440
EPSS Percentile 99.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

VulnCheck KEV 2024-04-08
CWE
CWE-22
Status published
Products (2)
igniterealtime/openfire < 4.4.2
org.igniterealtime.openfire/parent 0 - 4.5.0-betaMaven
Published Oct 24, 2019
Tracked Since Feb 18, 2026