Reflected Cross-Site Scripting in Openfire by Ignite Realtime
CVE-2019-20527
6.1MEDIUM
What is CVE-2019-20527?
Openfire version 4.4.1 by Ignite Realtime is susceptible to a reflected cross-site scripting (XSS) vulnerability. This occurs when unsanitized input is accepted from the serverURL parameter in the setup/setup-datasource-standard.jsp page, allowing attackers to inject malicious scripts into web pages viewed by users. If exploited, this vulnerability can lead to unauthorized actions on behalf of the user, potentially compromising sensitive information.
