CVE-2020-24604: XSS
A Reflected XSS vulnerability was discovered in Ignite Realtime Openfire version 4.5.1. The XSS vulnerability allows remote attackers to inject arbitrary web script or HTML via the GET request "searchName", "searchValue", "searchDescription", "searchDefaultValue","searchPlugin", "searchDescription" and "searchDynamic" in server-properties.jsp and security-audit-viewer.jsp
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-24604?
CVE-2020-24604 is classified as a medium severity reflected XSS vulnerability.
How do I fix CVE-2020-24604?
To fix CVE-2020-24604, upgrade Openfire to version 4.6.0 or newer where the vulnerability is patched.
What versions of Openfire are affected by CVE-2020-24604?
CVE-2020-24604 affects Openfire version 4.5.1.
Can CVE-2020-24604 be exploited remotely?
Yes, CVE-2020-24604 can be exploited remotely by attackers through specific GET requests.
What impact does CVE-2020-24604 have on users?
CVE-2020-24604 allows attackers to inject arbitrary web scripts or HTML into user sessions, potentially compromising user data.