Description
An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via alias to Manage Store Contents.
Remediation
References
https://cybersecurityworks.com/zerodays/cve-2019-20363-openfire.html
https://github.com/igniterealtime/Openfire/pull/1561
https://issues.igniterealtime.org/browse/OF-1955
Related Vulnerabilities
CVE-2020-12265 Vulnerability in npm package decompress-tar
CVE-2021-32822 Vulnerability in npm package hbs
CVE-2023-26487 Vulnerability in maven package org.webjars.npm:vega
CVE-2023-34189 Vulnerability in maven package org.apache.inlong:manager-web
CVE-2016-3088 Vulnerability in maven package org.apache.activemq:activemq-fileserver