CVE-2009-1595

EPSS 8.8%

Ignite Realtime Openfire Allows Users to Change Passwords of Arbitrary Accounts

發布日:2022/5/2修改日:2024/1/23

描述

The `jabber:iq:auth` implementation in `IQAuthHandler.java` in Ignite Realtime Openfire before 3.6.4 allows remote authenticated users to change the passwords of arbitrary accounts via a modified username element in a `passwd_change` action.

受影響套件(1)

參考連結(8)