PT-2020-10504 · Ignite Realtime · Ignite Realtime Openfire
Huriye Özdemir
·
Published
2020-03-18
·
Updated
2022-05-24
·
CVE-2019-20528
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Ignite Realtime Openfire version 4.4.1
Description
The issue allows for cross-site scripting (XSS) attacks via the "setup/setup-datasource-standard.jsp" endpoint, specifically through the
username parameter. This means an attacker could potentially inject malicious scripts into the webpage, affecting users who access the page. The issue was fixed in a later version.Recommendations
For Ignite Realtime Openfire version 4.4.1, update to version 4.4.2 to resolve the issue. As a temporary workaround, consider restricting access to the "setup/setup-datasource-standard.jsp" endpoint or avoiding the use of the
username parameter in this context until the update can be applied.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ignite Realtime Openfire