Description
Ignite Realtime Openfire before 4.4.1 has reflected XSS via an LDAP setup test.
Remediation
References
https://github.com/igniterealtime/Openfire/compare/cd0a573...5e5d9e5
https://github.com/igniterealtime/Openfire/pull/1441
Related Vulnerabilities
CVE-2017-5662 Vulnerability in maven package org.eclipse.birt.runtime.3_7_1:org.apache.batik.dom
CVE-2020-26256 Vulnerability in npm package fast-csv
CVE-2021-28170 Vulnerability in maven package org.glassfish:jakarta.el
CVE-2011-3376 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2021-21391 Vulnerability in npm package @ckeditor/ckeditor5-image