PT-2020-10502 · Ignite Realtime · Openfire
Published
2020-03-19
·
Updated
2022-05-24
·
CVE-2019-20526
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Ignite Realtime Openfire version 4.4.1
Description
The issue allows for XSS via the "setup/setup-datasource-standard.jsp"
password parameter. This means an attacker could potentially inject malicious scripts into the webpage, affecting users who access the page. The issue was fixed in version 4.4.2.Recommendations
For Ignite Realtime Openfire version 4.4.1, update to version 4.4.2 to resolve the issue. As a temporary workaround, consider restricting access to the "setup/setup-datasource-standard.jsp" page until the update can be applied. Avoid using the
password parameter in the affected page until the issue is resolved.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openfire