VendorsIgnite Realtimeopenfire4.4.1
Vulnerabilities

Ignite Realtime Igniterealtime Openfire 4.4.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2019-20525
Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp driver parameter.
Published 2020-03-19 · Modified
6.1EPSS 0.009
CVE-2019-20526
Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp password parameter.
Published 2020-03-19 · Modified
6.1EPSS 0.009
CVE-2019-20527
Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp serverURL parameter.
Published 2020-03-19 · Modified
6.1EPSS 0.009
CVE-2019-20528
Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp username parameter.
Published 2020-03-18 · Modified
6.1EPSS 0.009