CyberSec.Space Logo
CVEブラウザに戻る

CVE-2017-2815

HIGH
8.1
CVSS Severity Score
EPSS Score0.1550%
EPSS Percentile23.67th
Published2018年5月15日
Last Modified2024年11月21日

Vulnerability Description

An exploitable XML entity injection vulnerability exists in OpenFire User Import Export Plugin 2.6.0. A specially crafted web request can cause the retrieval of arbitrary files or denial of service. An authenticated attacker can send a crafted web request to trigger this vulnerability.

Affected Platforms (CPE)

📦
Igniterealtime

User Import Export

= 2.6.0

References & Advisories

関連する脆弱性情報