Vulnerability CVE-2024-25420


Published: 2024-03-26

Description:
An issue in Ignite Realtime Openfire v.4.9.0 and before allows a remote attacker to escalate privileges via the admin.authorizedJIDs system property component.

 References:
https://www.igniterealtime.org/projects/openfire/
https://github.com/igniterealtime/Openfire/blob/main/xmppserver/src/main/java/org/jivesoftware/openfire/admin/AdminManager.java
https://www.hackthebox.com/blog/openfire-cves-explained-CVE-2024-25420-CVE-2024-25421

Copyright 2026, cxsecurity.com

 

Back to Top