Description
Ignite Realtime Openfire 4.6.0 has plugins/clientcontrol/spark-form.jsp Reflective XSS.
Remediation
References
https://discourse.igniterealtime.org/t/openfire-4-6-0-has-reflective-xss-vulnerabilities/89296
Related Vulnerabilities
CVE-2017-1000228 Vulnerability in npm package ejs
CVE-2020-8147 Vulnerability in npm package utils-extend
CVE-2018-1000006 Vulnerability in npm package electron
CVE-2023-26476 Vulnerability in maven package org.xwiki.platform:xwiki-platform-livetable-ui
CVE-2016-4055 Vulnerability in maven package org.fujion.webjars:moment