📦

user_import_export

Vendor: igniterealtime

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 0 Remote Access
Total CVEs 1 Total Indexed
Avg. EPSS 0.93% Exploit Prob.
Latest CVE CVE-2017-2815 May 15

Security Vulnerability Index

Page 1 / 1
8.1 CVSS

An exploitable XML entity injection vulnerability exists in OpenFire User Import Export Plugin 2.6.0. A specially crafted web request can cause the retrieval of arbitrary files or denial of service. An authenticated attacker can send a crafted web request to trigger this vulnerability.

EPSS: 0.93%