CVE-2020-35127: XSS
Ignite Realtime Openfire 4.6.0 has plugins/bookmarks/create-bookmark.jsp Stored XSS.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-35127 vulnerability?
CVE-2020-35127 is a Stored Cross-Site Scripting (XSS) vulnerability in Ignite Realtime Openfire 4.6.0.
What is the severity of CVE-2020-35127 vulnerability?
The severity of CVE-2020-35127 vulnerability is medium with a CVSS score of 5.4.
How does the CVE-2020-35127 vulnerability impact Ignite Realtime Openfire 4.6.0?
The CVE-2020-35127 vulnerability allows attackers to execute malicious scripts in the context of a user's browser, potentially leading to session hijacking or defacement of the application.
How do I check if I am using Ignite Realtime Openfire 4.6.0?
To check if you are using Ignite Realtime Openfire 4.6.0, go to the application's administration panel and look for the version information.
How do I mitigate the CVE-2020-35127 vulnerability in Ignite Realtime Openfire 4.6.0?
To mitigate the CVE-2020-35127 vulnerability, upgrade Ignite Realtime Openfire to a patched version or apply the necessary security patches provided by the vendor.