CVE-2020-24604
- EPSS 0.98%
- Published 02.09.2020 15:15:10
- Last modified 21.11.2024 05:15:08
A Reflected XSS vulnerability was discovered in Ignite Realtime Openfire version 4.5.1. The XSS vulnerability allows remote attackers to inject arbitrary web script or HTML via the GET request "searchName", "searchValue", "searchDescription", "search...
CVE-2020-24602
- EPSS 1.14%
- Published 02.09.2020 15:15:10
- Last modified 21.11.2024 05:15:08
Ignite Realtime Openfire 4.5.1 has a reflected Cross-site scripting vulnerability which allows an attacker to execute arbitrary malicious URL via the vulnerable GET parameter searchName", "searchValue", "searchDescription", "searchDefaultValue","sear...
CVE-2020-24601
- EPSS 0.62%
- Published 02.09.2020 15:15:10
- Last modified 21.11.2024 05:15:07
In Ignite Realtime Openfire 4.5.1 a Stored Cross-site Vulnerability allows an attacker to execute an arbitrary malicious URL via the vulnerable POST parameter searchName", "alias" in the import certificate trusted page
CVE-2019-20526
- EPSS 0.47%
- Published 19.03.2020 18:15:15
- Last modified 21.11.2024 04:38:40
Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp password parameter.
CVE-2019-20525
- EPSS 0.47%
- Published 19.03.2020 18:15:15
- Last modified 21.11.2024 04:38:40
Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp driver parameter.
CVE-2019-20527
- EPSS 0.47%
- Published 19.03.2020 14:15:12
- Last modified 21.11.2024 04:38:40
Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp serverURL parameter.
CVE-2019-20528
- EPSS 0.47%
- Published 18.03.2020 19:15:17
- Last modified 21.11.2024 04:38:40
Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp username parameter.
CVE-2019-20365
- EPSS 1.23%
- Published 08.01.2020 17:15:11
- Last modified 21.11.2024 04:38:19
An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via search to the Users/Group search page.
CVE-2019-20366
- EPSS 1.66%
- Published 08.01.2020 17:15:11
- Last modified 21.11.2024 04:38:19
An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via isTrustStore to Manage Store Contents.
CVE-2019-20364
- EPSS 1.23%
- Published 08.01.2020 17:15:11
- Last modified 21.11.2024 04:38:18
An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via cacheName to SystemCacheDetails.jsp.