CVE-2015-6973 | Ignite Realtime Openfire 3.10.2 user-password.jsp cross-site request forgery (Exploit 133554 / EDB-38192)
A vulnerability classified as critical was found in Ignite Realtime Openfire 3.10.2. This vulnerability affects unknown code of the file user-password.jsp. The manipulation leads to cross-site request forgery.
This vulnerability was named CVE-2015-6973. The attack can be initiated remotely. Furthermore, there is an exploit available.