{"id":7698,"date":"2020-02-05T18:34:17","date_gmt":"2020-02-06T01:34:17","guid":{"rendered":"https:\/\/webdev.securin.xyz\/?post_type=zerodays&p=7698"},"modified":"2023-02-06T10:56:16","modified_gmt":"2023-02-06T17:56:16","slug":"cve-2020-24604-ignite-realtime-openfire","status":"publish","type":"zerodays","link":"https:\/\/webdev.securin.xyz\/zerodays\/cve-2020-24604-ignite-realtime-openfire\/","title":{"rendered":"CVE-2020-24604 – Multiple Cross Site Scripting in Openfire Product"},"content":{"rendered":"
A cross-site scripting (XSS) attack can cause arbitrary code (javascript) to run in a user\u2019s browser while the browser is connected to a trusted web site. The application targets your application\u2019s users and not the application itself, but it uses your application as the vehicle for the attack. XSS payload is executed whenever the user views the crafted POST request with XSS Payload in Openfire 4.5.0 Product.<\/p>\n","protected":false},"featured_media":13580,"parent":0,"menu_order":0,"template":"","vulnerability_categories":[],"acf":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/webdev.securin.xyz\/wp-json\/wp\/v2\/zerodays\/7698"}],"collection":[{"href":"https:\/\/webdev.securin.xyz\/wp-json\/wp\/v2\/zerodays"}],"about":[{"href":"https:\/\/webdev.securin.xyz\/wp-json\/wp\/v2\/types\/zerodays"}],"version-history":[{"count":11,"href":"https:\/\/webdev.securin.xyz\/wp-json\/wp\/v2\/zerodays\/7698\/revisions"}],"predecessor-version":[{"id":13657,"href":"https:\/\/webdev.securin.xyz\/wp-json\/wp\/v2\/zerodays\/7698\/revisions\/13657"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/webdev.securin.xyz\/wp-json\/wp\/v2\/media\/13580"}],"wp:attachment":[{"href":"https:\/\/webdev.securin.xyz\/wp-json\/wp\/v2\/media?parent=7698"}],"wp:term":[{"taxonomy":"vulnerability_categories","embeddable":true,"href":"https:\/\/webdev.securin.xyz\/wp-json\/wp\/v2\/vulnerability_categories?post=7698"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}