miko550 / CVE-2023-32315

Openfire Console Authentication Bypass Vulnerability with RCE plugin

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

openfire 4.0.3 not returning CSRF token

Fr0gZero opened this issue · comments

Good Afternoon,

the openfire 4.0.3 instance that i have does not return a csrf token from the login page.

The LFI seems to still be present as the following url still returns the logs: /setup/setup-s/%u002e%u002e/%u002e%u002e/log.jsp

any guidance of how to retrieve the CSRF token for this version?

Thank you