First published: Wed Jan 08 2020(Updated: )
An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via cacheName to SystemCacheDetails.jsp.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Igniterealtime Openfire | =4.4.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-20364 is an XSS issue discovered in Ignite Realtime Openfire 4.4.4 via the cacheName parameter in the SystemCacheDetails.jsp file.
The severity of CVE-2019-20364 is medium, with a CVSS score of 6.1.
CVE-2019-20364 allows an attacker to perform cross-site scripting (XSS) attacks on Ignite Realtime Openfire 4.4.4.
To mitigate CVE-2019-20364, update Ignite Realtime Openfire to a fixed version, such as 4.4.5 or later.
You can find more information about CVE-2019-20364 at the following references: [1] [2] [3]