Description
Ignite Realtime Openfire before 4.4.1 has reflected XSS via an LDAP setup test.
Remediation
References
https://github.com/igniterealtime/Openfire/compare/cd0a573...5e5d9e5
https://github.com/igniterealtime/Openfire/pull/1441
Related Vulnerabilities
CVE-2020-6428 Vulnerability in npm package electron
CVE-2019-10761 Vulnerability in npm package vm2
CVE-2021-26814 Vulnerability in npm package wazuh
CVE-2022-36909 Vulnerability in maven package org.jenkins-ci.plugins:openshift-deployer
CVE-2018-20801 Vulnerability in maven package org.webjars:highcharts