CVE-2019-20525: XSS
Published Mar 19, 2020
·Updated
Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp driver parameter.
Affected Software
1 affected component
igniterealtime Openfire=4.4.1
Event History
Mar 19, 2020
CVE Published
via MITRE·05:56 PM
Data Sourced
via MITRE·05:56 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for Ignite Realtime Openfire 4.4.1?
The vulnerability ID for Ignite Realtime Openfire 4.4.1 is CVE-2019-20525.
2
What is the title of the vulnerability for Ignite Realtime Openfire 4.4.1?
The title of the vulnerability for Ignite Realtime Openfire 4.4.1 is 'Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp driver paramet…'.
3
What is the severity rating of CVE-2019-20525?
CVE-2019-20525 has a severity rating of 6.1 (medium).
4
How does the vulnerability in Ignite Realtime Openfire 4.4.1 occur?
The vulnerability in Ignite Realtime Openfire 4.4.1 occurs through XSS via the setup/setup-datasource-standard.jsp driver parameter.
5
Is there any reference to learn more about CVE-2019-20525?
Yes, you can learn more about CVE-2019-20525 at the following URL: https://www.netsparker.com/web-applications-advisories/ns-19-015-reflected-cross-site-scripting-in-openfire/