Show filters
41 Total Results
Displaying 11-20 of 41
Sort by:
Attacker Value
Unknown

CVE-2020-24604

Disclosure Date: September 02, 2020 (last updated February 22, 2025)
A Reflected XSS vulnerability was discovered in Ignite Realtime Openfire version 4.5.1. The XSS vulnerability allows remote attackers to inject arbitrary web script or HTML via the GET request "searchName", "searchValue", "searchDescription", "searchDefaultValue","searchPlugin", "searchDescription" and "searchDynamic" in server-properties.jsp and security-audit-viewer.jsp
Attacker Value
Unknown

CVE-2020-24601

Disclosure Date: September 02, 2020 (last updated February 22, 2025)
In Ignite Realtime Openfire 4.5.1 a Stored Cross-site Vulnerability allows an attacker to execute an arbitrary malicious URL via the vulnerable POST parameter searchName", "alias" in the import certificate trusted page
Attacker Value
Unknown

CVE-2020-12772

Disclosure Date: May 12, 2020 (last updated February 21, 2025)
An issue was discovered in Ignite Realtime Spark 2.8.3 (and the ROAR plugin for it) on Windows. A chat message can include an IMG element with a SRC attribute referencing an external host's IP address. Upon access to this external host, the (NT)LM hashes of the user are sent with the HTTP request. This allows an attacker to collect these hashes, crack them, and potentially compromise the computer. (ROAR can be configured for automatic access. Also, access can occur if the user clicks.)
Attacker Value
Unknown

CVE-2019-20525

Disclosure Date: March 19, 2020 (last updated February 21, 2025)
Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp driver parameter.
Attacker Value
Unknown

CVE-2019-20526

Disclosure Date: March 19, 2020 (last updated February 21, 2025)
Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp password parameter.
Attacker Value
Unknown

CVE-2019-20527

Disclosure Date: March 19, 2020 (last updated February 21, 2025)
Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp serverURL parameter.
Attacker Value
Unknown

CVE-2019-20528

Disclosure Date: March 18, 2020 (last updated February 21, 2025)
Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp username parameter.
Attacker Value
Unknown

CVE-2019-20365

Disclosure Date: January 08, 2020 (last updated February 21, 2025)
An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via search to the Users/Group search page.
Attacker Value
Unknown

CVE-2019-20366

Disclosure Date: January 08, 2020 (last updated February 21, 2025)
An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via isTrustStore to Manage Store Contents.
Attacker Value
Unknown

CVE-2019-20364

Disclosure Date: January 08, 2020 (last updated February 21, 2025)
An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via cacheName to SystemCacheDetails.jsp.