First published: Thu Mar 19 2020(Updated: )
Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp password parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Igniterealtime Openfire | =4.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-20526 is a vulnerability in Ignite Realtime Openfire 4.4.1 that allows cross-site scripting (XSS) attacks through the password parameter in the setup/setup-datasource-standard.jsp page.
CVE-2019-20526 is considered a medium severity vulnerability with a CVSS score of 6.1.
CVE-2019-20526 affects Ignite Realtime Openfire version 4.4.1, allowing XSS attacks through the setup/setup-datasource-standard.jsp page.
To fix CVE-2019-20526, you should update Ignite Realtime Openfire to the latest version or apply the recommended patch provided by the vendor.
Yes, you can find more information about CVE-2019-20526 in the advisory provided by Netsparker: https://www.netsparker.com/web-applications-advisories/ns-19-015-reflected-cross-site-scripting-in-openfire/