First published: Thu Mar 19 2020(Updated: )
Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp serverURL parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Openfire | =4.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-20527 has a medium severity level due to its potential for exploitation via cross-site scripting (XSS).
To fix CVE-2019-20527, upgrade Openfire to version 4.4.2 or later where the vulnerability has been addressed.
CVE-2019-20527 affects users of Ignite Realtime Openfire version 4.4.1.
CVE-2019-20527 is classified as a reflected cross-site scripting (XSS) vulnerability.
The exploit vector for CVE-2019-20527 involves manipulating the serverURL parameter in the setup-datasource-standard.jsp page.