CVE-2015-6972 | Ignite Realtime Openfire 3.10.2 create-bookmark.jsp search cross site scripting (Exploit 133558 / EDB-38191)
A vulnerability classified as critical has been found in Ignite Realtime Openfire 3.10.2. This affects an unknown part of the file plugins/clientcontrol/create-bookmark.jsp. The manipulation of the argument search leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2015-6972. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.