PT-2020-10402 · Ignite Realtime · Ignite Realtime Openfire

Published

2020-01-08

·

Updated

2022-05-24

·

CVE-2019-20366

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Ignite Realtime Openfire version 4.4.4
Description A cross-site scripting (XSS) issue was discovered in the software. The issue is related to the isTrustStore function, which is used to manage store contents.
Recommendations For Ignite Realtime Openfire version 4.4.4, consider disabling the isTrustStore function to manage store contents until a patch is available.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-20366
GHSA-M6PR-XCRM-4QQP

Affected Products

Ignite Realtime Openfire