The jabber:iq:auth implementation in IQAuthHandler.java in Ignite Realtime Openfire before 3.6.4 allows remote authenticated users to change the passwords of arbitrary accounts via a modified username element in a passwd_change action.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| org.igniterealtime.openfire:parent(Maven) | 0 | 3.6.4 | N/A |
CVSS Metrics