CVE-2019-18394
CRITICAL EXPLOITED IN THE WILD NUCLEIIgnite Realtime Openfire < 4.4.2 - Server-Side Request Forgery via FaviconServlet
Title source: llmExploitation Summary
CVE-2019-18394 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io). EIP tracks 2 public exploits from researchers including dawetmaster, andikahilmy. A Nuclei detection template is also available.
AI-analyzed exploit summary This repository appears to be a fork or clone of the Openfire project itself, containing build scripts, Dockerfiles, and source code for the Openfire XMPP server. It does not contain any exploit code or proof-of-concept for CVE-2019-18394.
Description
A Server Side Request Forgery (SSRF) vulnerability in FaviconServlet.java in Ignite Realtime Openfire through 4.4.2 allows attackers to send arbitrary HTTP GET requests.
Exploits (2)
This repository appears to be a fork or clone of the Openfire project itself, containing build scripts, Dockerfiles, and source code for the Openfire XMPP server. It does not contain any exploit code or proof-of-concept for CVE-2019-18394.
This repository appears to be a fork or clone of the Openfire project itself, containing build scripts, Dockerfiles, and source code for the Openfire XMPP server. There is no exploit code or proof-of-concept for CVE-2019-18394 present in the provided files.
Nuclei Templates (1)
http.title:"openfire admin console" || http.title:"openfire"
title="openfire" || title="openfire admin console"
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H