Description
Ignite Realtime Openfire 4.6.0 has plugins/clientcontrol/spark-form.jsp Reflective XSS.
Remediation
References
https://discourse.igniterealtime.org/t/openfire-4-6-0-has-reflective-xss-vulnerabilities/89296
Related Vulnerabilities
CVE-2019-15138 Vulnerability in maven package org.webjars.npm:html-pdf
CVE-2010-4172 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2023-48223 Vulnerability in npm package fast-jwt
CVE-2023-50730 Vulnerability in maven package org.typelevel:grackle-core_2.13
CVE-2012-0393 Vulnerability in maven package org.apache.struts:struts2-core