CVE-2020-36956

Openfire 4.6.0 contains a stored cross-site scripting vulnerability in the nodejs plugin that allows attackers to inject malicious scripts through the 'path' parameter. Attackers can craft a payload with script tags to execute arbitrary JavaScript in the context of administrative users viewing the nodejs configuration page.
Configurations

No configuration.

History

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) Openfire 4.6.0 contiene una vulnerabilidad de cross-site scripting almacenado en el plugin de nodejs que permite a los atacantes inyectar scripts maliciosos a través del parámetro 'path'. Los atacantes pueden crear una carga útil con etiquetas de script para ejecutar JavaScript arbitrario en el contexto de usuarios administrativos que visualizan la página de configuración de nodejs.

26 Jan 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-26 18:16

Updated : 2026-04-15 00:35


NVD link : CVE-2020-36956

Mitre link : CVE-2020-36956

CVE.ORG link : CVE-2020-36956


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')