BIT-openfire-2020-24604

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/openfire/BIT-openfire-2020-24604.json
JSON Data
https://api.test.osv.dev/v1/vulns/BIT-openfire-2020-24604
Aliases
Published
2024-03-06T11:00:36.576Z
Modified
2024-03-06T11:25:28.861Z
Summary
[none]
Details

A Reflected XSS vulnerability was discovered in Ignite Realtime Openfire version 4.5.1. The XSS vulnerability allows remote attackers to inject arbitrary web script or HTML via the GET request "searchName", "searchValue", "searchDescription", "searchDefaultValue","searchPlugin", "searchDescription" and "searchDynamic" in server-properties.jsp and security-audit-viewer.jsp

Database specific
{
    "cpes": [
        "cpe:2.3:a:igniterealtime:openfire:4.5.1:*:*:*:*:*:*:*"
    ],
    "severity": "Medium"
}
References

Affected packages

Bitnami / openfire

Package

Name
openfire
Purl
pkg:bitnami/openfire

Severity

  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
4.5.1
Last affected
4.5.1