First published: Wed Jan 08 2020(Updated: )
An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via isTrustStore to Manage Store Contents.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
maven/org.igniterealtime.openfire:parent | <=4.4.4 | 4.5.0 |
Openfire | =4.4.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-20366 is classified as a cross-site scripting (XSS) vulnerability that can potentially lead to unauthorized actions on behalf of a user.
To remediate CVE-2019-20366, upgrade Ignite Realtime Openfire to a version that has addressed this issue.
CVE-2019-20366 specifically affects Ignite Realtime Openfire version 4.4.4.
Yes, CVE-2019-20366 can be exploited remotely if the vulnerable version of Openfire is accessible over the internet.
CVE-2019-20366 facilitates cross-site scripting (XSS) attacks, allowing attackers to inject malicious scripts into the web pages viewed by users.