First published: Fri Dec 11 2020(Updated: )
Ignite Realtime Openfire 4.6.0 has plugins/bookmarks/create-bookmark.jsp Stored XSS.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Igniterealtime Openfire | =4.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-35127 is a Stored Cross-Site Scripting (XSS) vulnerability in Ignite Realtime Openfire 4.6.0.
The severity of CVE-2020-35127 vulnerability is medium with a CVSS score of 5.4.
The CVE-2020-35127 vulnerability allows attackers to execute malicious scripts in the context of a user's browser, potentially leading to session hijacking or defacement of the application.
To check if you are using Ignite Realtime Openfire 4.6.0, go to the application's administration panel and look for the version information.
To mitigate the CVE-2020-35127 vulnerability, upgrade Ignite Realtime Openfire to a patched version or apply the necessary security patches provided by the vendor.