CVE-2019-20526: XSS
Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp password parameter.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-20526?
CVE-2019-20526 is a vulnerability in Ignite Realtime Openfire 4.4.1 that allows cross-site scripting (XSS) attacks through the password parameter in the setup/setup-datasource-standard.jsp page.
How severe is CVE-2019-20526?
CVE-2019-20526 is considered a medium severity vulnerability with a CVSS score of 6.1.
How does CVE-2019-20526 affect Ignite Realtime Openfire?
CVE-2019-20526 affects Ignite Realtime Openfire version 4.4.1, allowing XSS attacks through the setup/setup-datasource-standard.jsp page.
How can I fix CVE-2019-20526?
To fix CVE-2019-20526, you should update Ignite Realtime Openfire to the latest version or apply the recommended patch provided by the vendor.
Is there any additional information about CVE-2019-20526?
Yes, you can find more information about CVE-2019-20526 in the advisory provided by Netsparker: https://www.netsparker.com/web-applications-advisories/ns-19-015-reflected-cross-site-scripting-in-openfire/