Filtered by vendor Igniterealtime Subscriptions
Total 43 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2019-15488 1 Igniterealtime 1 Openfire 2024-11-21 N/A
Ignite Realtime Openfire before 4.4.1 has reflected XSS via an LDAP setup test.
CVE-2018-11688 1 Igniterealtime 1 Openfire 2024-11-21 N/A
Ignite Realtime Openfire before 3.9.2 is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability via a crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.
CVE-2017-2815 1 Igniterealtime 1 User Import Export 2024-11-21 N/A
An exploitable XML entity injection vulnerability exists in OpenFire User Import Export Plugin 2.6.0. A specially crafted web request can cause the retrieval of arbitrary files or denial of service. An authenticated attacker can send a crafted web request to trigger this vulnerability.