VYPR
Medium severity6.1NVD Advisory· Published Dec 12, 2020· Updated Jun 17, 2026

CVE-2020-35200

CVE-2020-35200

Description

Ignite Realtime Openfire 4.6.0 has plugins/clientcontrol/spark-form.jsp Reflective XSS.

Affected products

4
  • cpe:2.3:a:igniterealtime:openfire:4.6.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:igniterealtime:openfire:4.6.0:*:*:*:*:*:*:*
    • (no CPE)range: =4.6.0
  • Ignite Realtime/Openfiredescription
  • osv-coords
    Range: >= 4.6.0, <= 4.6.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.