First published: Wed Mar 18 2020(Updated: )
Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp username parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Openfire | =4.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-20528 is considered moderate due to the presence of reflected cross-site scripting (XSS).
To fix CVE-2019-20528, you should upgrade to a patched version of Ignite Realtime Openfire beyond 4.4.1.
CVE-2019-20528 affects Ignite Realtime Openfire version 4.4.1.
Yes, CVE-2019-20528 can be exploited without authentication through maliciously crafted URLs.
CVE-2019-20528 is classified as a reflected cross-site scripting (XSS) vulnerability.