CVE-2020-35202: XSS
Published Dec 12, 2020
·Updated
Ignite Realtime Openfire 4.6.0 has plugins/dbaccess/db-access.jsp sql Stored XSS.
Affected Software
1 affected component
igniterealtime Openfire=4.6.0
Event History
Dec 12, 2020
CVE Published
via MITRE·05:20 PM
Data Sourced
via MITRE·05:20 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for Ignite Realtime Openfire 4.6.0?
The vulnerability ID for Ignite Realtime Openfire 4.6.0 is CVE-2020-35202.
2
What is the severity level of CVE-2020-35202?
The severity level of CVE-2020-35202 is medium with a CVSS score of 5.4.
3
What is the description of CVE-2020-35202?
CVE-2020-35202 is a Stored XSS vulnerability in the db-access.jsp file of Ignite Realtime Openfire 4.6.0.
4
What software version is affected by CVE-2020-35202?
The Ignite Realtime Openfire version 4.6.0 is affected by CVE-2020-35202.
5
Is there an exploit available for CVE-2020-35202?
Yes, there is an exploit available for CVE-2020-35202. You can find more information at https://www.exploit-db.com/exploits/49235.