CVE-2020-36956: Openfire 4.6.0 - 'path' Stored XSS
Openfire 4.6.0 contains a stored cross-site scripting vulnerability in the nodejs plugin that allows attackers to inject malicious scripts through the 'path' parameter. Attackers can craft a payload with script tags to execute arbitrary JavaScript in the context of administrative users viewing the nodejs configuration page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-36956?
CVE-2020-36956 is classified as a medium-severity vulnerability due to its potential for stored cross-site scripting attacks.
How do I fix CVE-2020-36956?
To fix CVE-2020-36956, upgrade to a patched version of Openfire that addresses the stored XSS vulnerabilities.
Who is affected by CVE-2020-36956?
CVE-2020-36956 affects users of Openfire version 4.6.0 with the nodejs plugin enabled.
What kind of exploit is CVE-2020-36956?
CVE-2020-36956 is a stored cross-site scripting (XSS) vulnerability that allows injection of malicious scripts.
Can CVE-2020-36956 be exploited remotely?
Yes, CVE-2020-36956 can be exploited remotely by an attacker who crafts a payload targeting the affected application.