漏洞描述 Ignite Realtime Openfire是Ignite Realtime社区的一款采用Java开发且基于XMPP(前称Jabber,即时通讯协议)的跨平台开源实时协作(RTC)服务器,它能够构建高效率的即时通信服务器,并支持上万并发用户数量。 Ignite Realtime Openfire 4.6.0 存在跨站脚本漏洞,该漏洞源于 plugins/clientcontrol/spark-form.jsp Reflective XSS。
相关漏洞推荐 (CVE-2025-15010)腾达WH450 1.0.0.18 /goform/SafeUrlFilter栈缓冲区溢出漏洞 POC CVE-2019-4061: IBM BigFix Platform - Information Disclosure POC CVE-2023-40211: Post Grid <= 2.2.50 - Information Exposure via REST API POC CVE-2025-55749: XWiki - Information Disclosure POC 红海云eHR /RedseaPlatform/BossIndex.mob SQL 注入漏洞 XWiki Platform 文件读取漏洞(CVE-2025-55749) POC CVE-2024-6555: WP Popups - Information Disclosure POC CVE-2025-51586: PrestaShop - Information Disclosure POC CVE-2018-13317: TOTOLINK A3002RU 1.0.8 - Information Disclosure POC CVE-2019-19822: TOTOLINK/Realtek Routers - Information Disclosure POC CVE-2019-19823: TOTOLINK/Realtek Routers - Information Disclosure POC CVE-2024-8852: All-in-One WP Migration < 7.87 - Unauthenticated Information Disclosure 万户ezOFFICE协同管理平台 /defaultroot/platform/custom/customizecenter/js/getAutoCode.jsp;.js SQL 注入漏洞