First published: Wed Sep 02 2020(Updated: )
In Ignite Realtime Openfire 4.5.1 a Stored Cross-site Vulnerability allows an attacker to execute an arbitrary malicious URL via the vulnerable POST parameter searchName", "alias" in the import certificate trusted page
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Openfire | =4.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-24601 is classified as a high severity vulnerability due to its potential for stored cross-site scripting attacks.
To mitigate CVE-2020-24601, upgrade to Openfire version 4.5.2 or later, where the vulnerability has been addressed.
CVE-2020-24601 affects users of Ignite Realtime Openfire version 4.5.1.
CVE-2020-24601 is a stored cross-site scripting vulnerability that allows for arbitrary URL execution.
The vulnerability in CVE-2020-24601 involves the POST parameters 'searchName' and 'alias' on the import certificate trusted page.