Description
Ignite Realtime Openfire before 4.4.1 has reflected XSS via an LDAP setup test.
Remediation
References
https://github.com/igniterealtime/Openfire/compare/cd0a573...5e5d9e5
https://github.com/igniterealtime/Openfire/pull/1441
Related Vulnerabilities
CVE-2022-21653 Vulnerability in maven package org.typelevel:jawn-parser_3
CVE-2021-21277 Vulnerability in maven package org.webjars.npm:angular-expressions
CVE-2023-5217 Vulnerability in npm package electron
CVE-2023-39522 Vulnerability in npm package @goauthentik/api
CVE-2023-46604 Vulnerability in maven package org.apache.activemq:activemq-client