← Back to CVE List

CVE-2020-24604

Published: 2020-09-02T15:15Z
Last Modified: 2024-11-21T05:15Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
A Reflected XSS vulnerability was discovered in Ignite Realtime Openfire version 4.5.1. The XSS vulnerability allows remote attackers to inject arbitrary web script or HTML via the GET request "searchName", "searchValue", "searchDescription", "searchDefaultValue","searchPlugin", "searchDescription" and "searchDynamic" in server-properties.jsp and security-audit-viewer.jsp > MITRE Terms of Use apply – see LICENSE‑MITRE.txt