← Back

User Import Export

user_import_export

Vendor: Igniterealtime • 1 CVE

CVEs (1)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Igniterealtime
1User Import Export
Nov 21, 2024
May 15, 2018
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
An exploitable XML entity injection vulnerability exists in OpenFire User Import Export Plugin 2.6.0. A specially crafted web request can cause the retrieval of arbitrary files or denial of service. An authenticated atta...Show more
An exploitable XML entity injection vulnerability exists in OpenFire User Import Export Plugin 2.6.0. A specially crafted web request can cause the retrieval of arbitrary files or denial of service. An authenticated attacker can send a crafted web request to trigger this vulnerability.Show less