CVE-2017-15911
Last modified
CVE-2017-15911 is a vulnerability of currently unknown severity. The Admin Console in Ignite Realtime Openfire Server before 4.1.7 allows arbitrary client-side JavaScript code execution on victims who click a crafted setup/setup-host-settings.jsp?domain= link, aka XSS. Session ID and data theft may follow as well as the possibility of bypassing CSRF protections, injection of iframes to establish communication channels, etc. EPSS estimates a 0.73% chance of exploitation in the next 30 days.
Description
The Admin Console in Ignite Realtime Openfire Server before 4.1.7 allows arbitrary client-side JavaScript code execution on victims who click a crafted setup/setup-host-settings.jsp?domain= link, aka XSS. Session ID and data theft may follow as well as the possibility of bypassing CSRF protections, injection of iframes to establish communication channels, etc. The vulnerability is present after login into the application.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Igniterealtime | Openfire | <= 4.1.6 |
References
- https://becomepentester.blogspot.ae/2017/10/Cross-Site-Scripting-Openfire-4.1.6-CVE-2017-15911.htmlIssue Tracking, Third Party Advisory
- https://issues.igniterealtime.org/browse/OF-1417Issue Tracking, Vendor Advisory
- https://becomepentester.blogspot.ae/2017/10/Cross-Site-Scripting-Openfire-4.1.6-CVE-2017-15911.htmlIssue Tracking, Third Party Advisory
- https://issues.igniterealtime.org/browse/OF-1417Issue Tracking, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-15911?
How severe is CVE-2017-15911?
How do I fix CVE-2017-15911?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-15897Node.js had a bug in versions 8.X and 9.X which caused buffe…3.1
- CVE-2017-15906The process_open function in sftp-server.c in OpenSSH before…5.3
- CVE-2017-15907SQL injection vulnerability in phpCollab 2.5.1 and earlier a…
- CVE-2017-15908In systemd 223 through 235, a remote DNS server can respond …7.5
- CVE-2017-15909D-Link DGS-1500 Ax devices before 2.51B021 have a hardcoded …
- CVE-2017-1591IBM WebSphere DataPower Appliances 7.0.0 through 7.6 is vuln…
- CVE-2017-15913The Installer in Whale allows DLL hijacking.
- CVE-2017-15914Incorrect implementation of access controls allows remote us…
- CVE-2017-15917In Paessler PRTG Network Monitor 17.3.33.2830, it's possible…
- CVE-2017-15918Sera 1.2 stores the user's login password in plain text in t…
- CVE-2017-15919The ultimate-form-builder-lite plugin before 1.3.7 for WordP…
- CVE-2017-1592IBM Rational Quality Manager and IBM Rational Collaborative …5.4
Are you affected by CVE-2017-15911?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
