CVE-2020-24604: Ignite Realtime Openfire
Medium severity, CVSS 6.1. EPSS: 1.2% chance of exploitation in the next 30 days.
A Reflected XSS vulnerability was discovered in Ignite Realtime Openfire version 4.5.1. The XSS vulnerability allows remote attackers to inject arbitrary web script or HTML via the GET request "searchName", "searchValue", "searchDescription", "searchDefaultValue","searchPlugin", "searchDescription" and "searchDynamic" in server-properties.jsp and security-audit-viewer.jsp
Affected products
- Ignite Realtime Openfire: version 4.5.1 only
Published 2020-09-02. Last modified 2026-06-17.