CVE-2019-20365: XSS
Published Jan 8, 2020
·Updated
An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via search to the Users/Group search page.
Affected Software
1 affected component
igniterealtime Openfire=4.4.4
Event History
Jan 8, 2020
CVE Published
via MITRE·04:27 PM
Data Sourced
via MITRE·04:27 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-20365?
The severity of CVE-2019-20365 is medium.
2
How does CVE-2019-20365 affect Ignite Realtime Openfire?
CVE-2019-20365 affects Ignite Realtime Openfire version 4.4.4.
3
What is the Common Weakness Enumeration (CWE) ID for CVE-2019-20365?
The Common Weakness Enumeration (CWE) ID for CVE-2019-20365 is CWE-79.
4
What is the recommended fix for CVE-2019-20365?
Upgrade to a fixed version of Ignite Realtime Openfire.
5
Where can I find more information about CVE-2019-20365?
More information about CVE-2019-20365 can be found at the following references: [1] [2] [3].