OpenFire 4.0.1 Cross Site Request Forgery / Cross Site Scripting

OpenFire versions 3.10.2 through 4.0.1 suffer from cross site request forgery and cross site scripting vulnerabilities. These issues are similar as findings discovered by hyp3rlinx but leverage different pages.

Leave a Reply