Vulnerabilities > Igniterealtime > Openfire > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-03-19 CVE-2019-20527 Cross-site Scripting vulnerability in Igniterealtime Openfire 4.4.1
Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp serverURL parameter.
network
low complexity
igniterealtime CWE-79
6.1
2020-03-18 CVE-2019-20528 Cross-site Scripting vulnerability in Igniterealtime Openfire 4.4.1
Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp username parameter.
network
low complexity
igniterealtime CWE-79
6.1
2020-01-08 CVE-2019-20366 Cross-site Scripting vulnerability in Igniterealtime Openfire 4.4.4
An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via isTrustStore to Manage Store Contents.
network
low complexity
igniterealtime CWE-79
6.1
2020-01-08 CVE-2019-20365 Cross-site Scripting vulnerability in Igniterealtime Openfire 4.4.4
An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via search to the Users/Group search page.
network
low complexity
igniterealtime CWE-79
6.1
2020-01-08 CVE-2019-20364 Cross-site Scripting vulnerability in Igniterealtime Openfire 4.4.4
An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via cacheName to SystemCacheDetails.jsp.
network
low complexity
igniterealtime CWE-79
6.1
2020-01-08 CVE-2019-20363 Cross-site Scripting vulnerability in Igniterealtime Openfire 4.4.4
An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via alias to Manage Store Contents.
network
low complexity
igniterealtime CWE-79
6.1
2019-10-24 CVE-2019-18393 Path Traversal vulnerability in Igniterealtime Openfire
PluginServlet.java in Ignite Realtime Openfire through 4.4.2 does not ensure that retrieved files are located under the Openfire home directory, aka a directory traversal vulnerability.
network
low complexity
igniterealtime CWE-22
5.3
2019-08-23 CVE-2019-15488 Cross-site Scripting vulnerability in Igniterealtime Openfire
Ignite Realtime Openfire before 4.4.1 has reflected XSS via an LDAP setup test.
network
low complexity
igniterealtime CWE-79
6.1
2018-06-13 CVE-2018-11688 Cross-site Scripting vulnerability in Igniterealtime Openfire 3.7.1
Ignite Realtime Openfire before 3.9.2 is vulnerable to cross-site scripting, caused by improper validation of user-supplied input.
network
low complexity
igniterealtime CWE-79
6.1
2017-10-26 CVE-2017-15911 Cross-site Scripting vulnerability in Igniterealtime Openfire
The Admin Console in Ignite Realtime Openfire Server before 4.1.7 allows arbitrary client-side JavaScript code execution on victims who click a crafted setup/setup-host-settings.jsp?domain= link, aka XSS.
network
low complexity
igniterealtime CWE-79
4.8