HTTP: Openfire CVE-2015-7707 Privilege Escalation

This signature detects attempts to exploit a known vulnerability against Openfire. A successful attack can lead to elevation of privilege and arbitrary code execution.

Extended Description

Ignite Realtime Openfire 3.10.2 allows remote authenticated users to gain administrator access via the isadmin parameter to user-edit-form.jsp.

Affected Products

Igniterealtime openfire

References

CVE: CVE-2015-7707

Short Name
HTTP:CTS:OPENFIRE-PRIV-ESC
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2015-7707 Escalation Openfire Privilege
Release Date
12/02/2019
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3337
False Positive
Unknown
Vendors

Igniterealtime

CVSS Score

6.5

Found a potential security threat?