PT-2020-15762 · Ignite Realtime · Openfire

Published

2020-09-02

·

Updated

2024-03-06

·

CVE-2020-24602

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Ignite Realtime Openfire version 4.5.1
Description The issue allows an attacker to execute arbitrary malicious code via a reflected Cross-site scripting vulnerability. This is achieved by exploiting the vulnerable GET parameters searchName, searchValue, searchDescription, searchDefaultValue, searchPlugin, and searchDynamic in the Server Properties and Security Audit Viewer JSP page.
Recommendations For Ignite Realtime Openfire version 4.5.1, as a temporary workaround, consider restricting access to the Server Properties and Security Audit Viewer JSP page until a patch is available. Avoid using the parameters searchName, searchValue, searchDescription, searchDefaultValue, searchPlugin, and searchDynamic in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

BIT-OPENFIRE-2020-24602
CVE-2020-24602

Affected Products

Openfire