CVE-2019-20528: XSS
Published Mar 18, 2020
·Updated
Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp username parameter.
Affected Software
1 affected component
igniterealtime Openfire=4.4.1
Event History
Mar 18, 2020
CVE Published
via MITRE·06:36 PM
Data Sourced
via MITRE·06:36 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-20528?
The severity of CVE-2019-20528 is considered moderate due to the presence of reflected cross-site scripting (XSS).
2
How do I fix CVE-2019-20528?
To fix CVE-2019-20528, you should upgrade to a patched version of Ignite Realtime Openfire beyond 4.4.1.
3
What versions of Openfire are affected by CVE-2019-20528?
CVE-2019-20528 affects Ignite Realtime Openfire version 4.4.1.
4
Can CVE-2019-20528 be exploited without authentication?
Yes, CVE-2019-20528 can be exploited without authentication through maliciously crafted URLs.
5
What type of vulnerability is CVE-2019-20528?
CVE-2019-20528 is classified as a reflected cross-site scripting (XSS) vulnerability.