Total vulnerabilities in the database
PluginServlet.java in Ignite Realtime Openfire through 4.4.2 does not ensure that retrieved files are located under the Openfire home directory, aka a directory traversal vulnerability.
Software | From | Fixed in |
---|---|---|
igniterealtime / openfire | - | 4.4.2.x |
![]() |
- | 4.5.0-beta |