CVE-2015-7707: Medium severity openfire vulnerability
Published Oct 5, 2015
·Updated
Ignite Realtime Openfire 3.10.2 allows remote authenticated users to gain administrator access via the isadmin parameter to user-edit-form.jsp.
Affected Software
1 affected component
igniterealtime Openfire=3.10.2
Event History
Oct 5, 2015
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-7707?
CVE-2015-7707 is rated as a high severity vulnerability due to its potential for privilege escalation.
2
How do I fix CVE-2015-7707?
To fix CVE-2015-7707, upgrade to a patched version of Openfire that addresses this vulnerability.
3
Who is affected by CVE-2015-7707?
CVE-2015-7707 affects installations of Ignite Realtime Openfire version 3.10.2.
4
What type of vulnerability is CVE-2015-7707?
CVE-2015-7707 is a privilege escalation vulnerability that allows remote authenticated users to gain administrator access.
5
Can CVE-2015-7707 be exploited remotely?
Yes, CVE-2015-7707 can be exploited remotely by authenticated users.