Cross-Site Scripting Vulnerability in Ignite Realtime Openfire
CVE-2019-20364
6.1MEDIUM
What is CVE-2019-20364?
An XSS vulnerability was identified in Ignite Realtime Openfire 4.4.4, specifically through the 'cacheName' parameter in SystemCacheDetails.jsp. This flaw could allow attackers to inject malicious scripts into the web interface, potentially compromising user data and creating security risks for affected systems. Proper input validation and sanitization measures are recommended to mitigate this issue.
