PT-2020-10402 · Ignite Realtime · Ignite Realtime Openfire
Published
2020-01-08
·
Updated
2022-05-24
·
CVE-2019-20366
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Ignite Realtime Openfire version 4.4.4
Description
A cross-site scripting (XSS) issue was discovered in the software. The issue is related to the
isTrustStore function, which is used to manage store contents.Recommendations
For Ignite Realtime Openfire version 4.4.4, consider disabling the
isTrustStore function to manage store contents until a patch is available.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ignite Realtime Openfire