Description
Ignite Realtime Openfire before 4.4.1 has reflected XSS via an LDAP setup test.
Remediation
References
https://github.com/igniterealtime/Openfire/compare/cd0a573...5e5d9e5
https://github.com/igniterealtime/Openfire/pull/1441
Related Vulnerabilities
CVE-2023-47324 Vulnerability in maven package org.silverpeas.core:silverpeas-core-web
CVE-2022-40309 Vulnerability in maven package org.apache.archiva:maven2-repository
CVE-2022-24913 Vulnerability in maven package com.fasterxml.util:java-merge-sort
CVE-2017-2610 Vulnerability in maven package org.jenkins-ci.main:jenkins-war
CVE-2021-3312 Vulnerability in maven package org.opencms:opencms-core