High severity8.1NVD Advisory· Published May 15, 2018· Updated Jun 17, 2026
CVE-2017-2815
CVE-2017-2815
Description
An exploitable XML entity injection vulnerability exists in OpenFire User Import Export Plugin 2.6.0. A specially crafted web request can cause the retrieval of arbitrary files or denial of service. An authenticated attacker can send a crafted web request to trigger this vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- cpe:2.3:a:igniterealtime:user_import_export:2.6.0:*:*:*:*:openfire:*:*
- Talos/Open Fire User Import Export Pluginv5Range: 2.6.0
Patches
Vulnerability mechanics
References
1- www.talosintelligence.com/vulnerability_reports/TALOS-2017-0316nvdThird Party Advisory
News mentions
0No linked articles in our index yet.