CVE-2019-20366: XSS
Published Jan 8, 2020
·Updated
An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via isTrustStore to Manage Store Contents.
Affected Software
2 affected componentsFixes available
maven/org.igniterealtime.openfire:parent<=4.4.4
4.5.0
igniterealtime Openfire=4.4.4
Event History
Jan 8, 2020
CVE Published
via MITRE·04:26 PM
Data Sourced
via MITRE·04:26 PM
Description
May 24, 2022
Advisory Published
10:01 PM
Frequently Asked Questions
1
What is the severity of CVE-2019-20366?
CVE-2019-20366 is classified as a cross-site scripting (XSS) vulnerability that can potentially lead to unauthorized actions on behalf of a user.
2
How do I fix CVE-2019-20366?
To remediate CVE-2019-20366, upgrade Ignite Realtime Openfire to a version that has addressed this issue.
3
What systems are affected by CVE-2019-20366?
CVE-2019-20366 specifically affects Ignite Realtime Openfire version 4.4.4.
4
Can CVE-2019-20366 be exploited remotely?
Yes, CVE-2019-20366 can be exploited remotely if the vulnerable version of Openfire is accessible over the internet.
5
What type of attack does CVE-2019-20366 facilitate?
CVE-2019-20366 facilitates cross-site scripting (XSS) attacks, allowing attackers to inject malicious scripts into the web pages viewed by users.