Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

J5Steam

#21332of 53,624
11.5Total CVSS
Vulnerabilities · 2
Medium
2
PT-2020-17289
6.1
2020-12-12
Ignite Realtime · Openfire · CVE-2020-35200
**Name of the Vulnerable Software and Affected Versions** Ignite Realtime Openfire version 4.6.0 **Description** The issue is related to a Reflective XSS in the plugins/clientcontrol/spark-form.jsp file. **Recommendations** For Ignite Realtime Openfire version 4.6.0, consider restricting access to the spark-form.jsp file as a temporary workaround until a patch is available.
PT-2020-17262
5.4
2020-12-11
Ignite Realtime · Openfire · CVE-2020-35127
**Name of the Vulnerable Software and Affected Versions** Ignite Realtime Openfire version 4.6.0 **Description** The issue is related to a Stored XSS in the create-bookmark.jsp file within the bookmarks plugin. **Recommendations** For Ignite Realtime Openfire version 4.6.0, consider restricting access to the `create-bookmark.jsp` file in the bookmarks plugin until a patch is available.