CVE Series: Openfire (CVE-2023-32315)
Course Content
Description
CVE-2023-32315 is a path traversal vulnerability affecting the Openfire application, specifically the admin console, which allows an unauthenticated attacker to create an account on any unpatched server instance. Utilizing this attack vector, attackers can then achieve RCE on the underlying server. This application has been downloaded nearly 9 millions times and the vulnerability has been exploited in the wild.
Target Audience
This course is for seasoned red teamers, penetration testers, security and vulnerability assessment analysts, and system administrators who want to know how to exploit and protect against the latest vulnerabilities impacting enterprise systems.
Course Level
Intermediate. The course is best suited for those with a basic understanding of the CLI, Web traffic, and software management.
Prerequisites
Linux command line basics, web application protocols, and Java application basics.
Course Goals
By the end of this course, you should be able to:
Helpful Links
https://learningsomecti.medium.com/path-traversal-to-rce-openfire-cve-2023-32315-6a8bf0285fcc