Description
An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via cacheName to SystemCacheDetails.jsp.
Remediation
References
https://cybersecurityworks.com/zerodays/cve-2019-20364-openfire.html
https://github.com/igniterealtime/Openfire/pull/1561
https://issues.igniterealtime.org/browse/OF-1955
Related Vulnerabilities
CVE-2023-44487 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2020-12827 Vulnerability in maven package org.webjars.npm:mjml
CVE-2022-35915 Vulnerability in npm package openzeppelin-solidity
CVE-2023-37944 Vulnerability in maven package org.datadog.jenkins.plugins:datadog
CVE-2023-22465 Vulnerability in maven package org.http4s:http4s-core_2.12