6.5
CVSSv2

CVE-2015-7707

Published: 05/10/2015 Updated: 01/07/2017
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Ignite Realtime Openfire 3.10.2 allows remote authenticated users to gain administrator access via the isadmin parameter to user-edit-form.jsp.

Vulnerable Product Search on Vulmon Subscribe to Product

igniterealtime openfire 3.10.2

Vendor Advisories

Ignite Realtime Openfire 3102 allows remote authenticated users to gain administrator access via the isadmin parameter to user-edit-formjsp ...

Exploits

[+] Credits: hyp3rlinx [+] Website: hyp3rlinxaltervistaorg [+] Source: hyp3rlinxaltervistaorg/advisories/AS-OPENFIRE-PRIV-ESCALATIONtxt Vendor: ================================ wwwigniterealtimeorg/projects/openfire wwwigniterealtimeorg/downloads/indexjsp Product: ================================ Openfire 3102 Openfire i ...