Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Vulnerabilities in the Openfire Admin Console

Summary

Two vulnerabilities in the Openfire Admin Console: an unauthenticated full-read SSRF through FaviconServlet (CVE-2019-18394) that can reach internal services, and a Windows-only arbitrary file read via PluginServlet path handling (CVE-2019-18393) that requires an admin account.
Published
Collected

original ↗

Related coverage

back