Description
Ignite Realtime Openfire before 4.4.1 has reflected XSS via an LDAP setup test.
Remediation
References
https://github.com/igniterealtime/Openfire/compare/cd0a573...5e5d9e5
https://github.com/igniterealtime/Openfire/pull/1441
Related Vulnerabilities
CVE-2023-44487 Vulnerability in maven package org.apache.tomcat:tomcat-coyote
CVE-2023-25572 Vulnerability in npm package react-admin
CVE-2020-28168 Vulnerability in maven package org.webjars.npm:axios
CVE-2021-32661 Vulnerability in npm package plugin-techdocs
CVE-2017-14063 Vulnerability in maven package org.asynchttpclient:async-http-client-project