Lucene search

K
attackerkbAttackerKBAKB:3ED26C7B-CE17-447D-BECC-CC9F425C1F9C
HistoryOct 24, 2019 - 12:00 a.m.

CVE-2019-18393

2019-10-2400:00:00
attackerkb.com
14

EPSS

0.002

Percentile

52.8%

PluginServlet.java in Ignite Realtime Openfire through 4.4.2 does not ensure that retrieved files are located under the Openfire home directory, aka a directory traversal vulnerability.

Recent assessments:

ericalexanderorg at August 04, 2020 4:44pm UTC reported:

More detail:
<https://swarm.ptsecurity.com/openfire-admin-console/&gt;

Stupid easy

> GET /plugins/search/…\conf\openfire.xml

Assessed Attacker Value: 5
Assessed Attacker Value: 5Assessed Attacker Value: 4

EPSS

0.002

Percentile

52.8%

Related for AKB:3ED26C7B-CE17-447D-BECC-CC9F425C1F9C