Cross-Site Scripting Vulnerability in Openfire by Ignite Realtime
CVE-2019-20526
6.1MEDIUM
What is CVE-2019-20526?
Ignite Realtime Openfire version 4.4.1 contains a Cross-Site Scripting vulnerability that can be exploited through the password parameter in the setup/setup-datasource-standard.jsp page. Attackers can leverage this flaw to inject malicious scripts, potentially compromising user accounts and sensitive information.
