CVE-2020-35199: XSS
Published Dec 12, 2020
·Updated
Ignite Realtime Openfire 4.6.0 has create-bookmark.jsp groupchatJID Stored XSS.
Affected Software
1 affected component
igniterealtime Openfire=4.6.0
Event History
Dec 12, 2020
CVE Published
via MITRE·05:20 PM
Data Sourced
via MITRE·05:20 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of Ignite Realtime Openfire 4.6.0?
The vulnerability ID of Ignite Realtime Openfire 4.6.0 is CVE-2020-35199.
2
What is the severity rating of CVE-2020-35199?
The severity rating of CVE-2020-35199 is medium, with a severity value of 5.4.
3
What is the affected software?
The affected software is Ignite Realtime Openfire 4.6.0.
4
What is the CWE ID of CVE-2020-35199?
The CWE ID of CVE-2020-35199 is CWE-79.
5
Is there a known exploit for CVE-2020-35199?
Yes, there is a known exploit for CVE-2020-35199. You can find more information at https://www.exploit-db.com/exploits/49233.