CVE-2020-24601: Cross-site Scripting
(updated )
In Ignite Realtime Openfire, a stored cross-site scripting vulnerability allows an attacker to execute an arbitrary malicious URL via the vulnerable POST parameters searchName
and alias
in the import certificate trusted page.
References
Detect and mitigate CVE-2020-24601 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →