OpenFire 4.0.1 Cross Site Request Forgery / Cross Site Scripting
Posted by deepcore on July 7, 2016 – 2:12 am
OpenFire versions 3.10.2 through 4.0.1 suffer from cross site request forgery and cross site scripting vulnerabilities. These issues are similar as findings discovered by hyp3rlinx but leverage different pages.
Post a reply
You must be logged in to post a comment.