CVE-2019-20527: XSS
Published Mar 19, 2020
·Updated
Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp serverURL parameter.
Affected Software
1 affected component
igniterealtime Openfire=4.4.1
Event History
Mar 19, 2020
CVE Published
via MITRE·01:51 PM
Data Sourced
via MITRE·01:51 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-20527?
CVE-2019-20527 has a medium severity level due to its potential for exploitation via cross-site scripting (XSS).
2
How do I fix CVE-2019-20527?
To fix CVE-2019-20527, upgrade Openfire to version 4.4.2 or later where the vulnerability has been addressed.
3
Who is affected by CVE-2019-20527?
CVE-2019-20527 affects users of Ignite Realtime Openfire version 4.4.1.
4
What type of vulnerability is CVE-2019-20527?
CVE-2019-20527 is classified as a reflected cross-site scripting (XSS) vulnerability.
5
What is the exploit vector for CVE-2019-20527?
The exploit vector for CVE-2019-20527 involves manipulating the serverURL parameter in the setup-datasource-standard.jsp page.