Cross-site request forgery in Openfire - CVE-2015-6973

 

Cross-site request forgery in Openfire - CVE-2015-6973

Published: October 12, 2019


Vulnerability identifier: #VU21739
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-6973
CWE-ID: CWE-352
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to perform cross-site request forgery attacks.

The vulnerability exists due to insufficient validation of the HTTP request origin. A remote attacker can trick the victim to visit a specially crafted web page and perform various actions on behalf of the victim, such as change victim's password, create new users, edit server settings, etc.


Affected software

Openfire
Arch Linux
Gentoo Linux

How to mitigate CVE-2015-6973

Install update from vendor's website.

Openfire - update to 3.10.3

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins