The jabber:iq:auth implementation in IQAuthHandler.java in Ignite Realtime Openfire before 3.6.4 allows remote authenticated users to change the passwords of arbitrary accounts via a modified username element in a passwd_change action.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2009-05-11 14:30
Updated : 2025-04-09 00:30
NVD link : CVE-2009-1595
Mitre link : CVE-2009-1595
CVE.ORG link : CVE-2009-1595
JSON object : View
Products Affected
igniterealtime
- openfire
CWE
CWE-287
Improper Authentication