Page 4 of 35 results (0.003 seconds)

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 1

An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via cacheName to SystemCacheDetails.jsp. Se descubrió un problema de tipo XSS en Ignite Realtime Openfire versión 4.4.4, por medio de cacheName en el archivo SystemCacheDetails.jsp. • https://cybersecurityworks.com/zerodays/cve-2019-20364-openfire.html https://github.com/igniterealtime/Openfire/pull/1561 https://issues.igniterealtime.org/browse/OF-1955 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 1

An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via search to the Users/Group search page. Se descubrió un problema de tipo XSS en Ignite Realtime Openfire versión 4.4.4, por medio de una búsqueda en la página Users/Group search. • https://cybersecurityworks.com/zerodays/cve-2019-20365-openfire.html https://github.com/igniterealtime/Openfire/pull/1561 https://issues.igniterealtime.org/browse/OF-1955 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 1

An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via isTrustStore to Manage Store Contents. Se descubrió un problema de tipo XSS en Ignite Realtime Openfire versión 4.4.4, por medio de isTrustStore en Manage Store Contents. • https://cybersecurityworks.com/zerodays/cve-2019-20366-openfire.html https://github.com/igniterealtime/Openfire/pull/1561 https://issues.igniterealtime.org/browse/OF-1955 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 9.8EPSS: 56%CPEs: 1EXPL: 0

A Server Side Request Forgery (SSRF) vulnerability in FaviconServlet.java in Ignite Realtime Openfire through 4.4.2 allows attackers to send arbitrary HTTP GET requests. Una vulnerabilidad de tipo Server Side Request Forgery (SSRF) en el archivo FaviconServlet.java en Ignite Realtime Openfire versiones hasta 4.4.2, permite a atacantes enviar peticiones HTTP GET arbitrarias. • https://github.com/igniterealtime/Openfire/pull/1497 https://swarm.ptsecurity.com/openfire-admin-console • CWE-918: Server-Side Request Forgery (SSRF) •

CVSS: 5.3EPSS: 0%CPEs: 1EXPL: 0

PluginServlet.java in Ignite Realtime Openfire through 4.4.2 does not ensure that retrieved files are located under the Openfire home directory, aka a directory traversal vulnerability. El archivo PluginServlet.java en Ignite Realtime Openfire versiones hasta 4.4.2, no garantiza que los archivos recuperados se encuentren en el directorio de inicio de Openfire, también se conoce como una vulnerabilidad de salto de directorio. • https://github.com/igniterealtime/Openfire/pull/1498 https://swarm.ptsecurity.com/openfire-admin-console • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •