Securin Zero-Days

CVE-2020-24602 – Multiple Cross-Site Scripting in Openfire Product

Severity:Medium

Vendor

Openfire

Affected Product

Ignite Realtime Openfire

CVE

CVE-2020-24602

Securin ID

2020-CSW-01-1040

Status

Fixed

Date

February 4, 2020

Description

 A cross-site scripting (XSS) attack can cause arbitrary code (javascript) to run in a user’s browser while the browser is connected to a trusted web site. The application targets your application’s users and not the application itself, but it uses your application as the vehicle for the attack. XSS payload is executed whenever the user views the crafted POST request with XSS Payload in Openfire 4.5.0 Product.

Proof of Concept (POC):

The following vulnerability was tested on Openfire version 4.5.0 Product.

Issue 01: Reflected cross-site scripting (POST Request)

Figure 01: System Properties page