Description
An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via cacheName to SystemCacheDetails.jsp.
Remediation
References
https://cybersecurityworks.com/zerodays/cve-2019-20364-openfire.html
https://github.com/igniterealtime/Openfire/pull/1561
https://issues.igniterealtime.org/browse/OF-1955
Related Vulnerabilities
CVE-2020-8137 Vulnerability in npm package fastify
CVE-2021-30109 Vulnerability in npm package froala-editor
CVE-2020-26217 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2021-33036 Vulnerability in maven package org.apache.hadoop:hadoop-yarn-server-common
CVE-2020-23622 Vulnerability in maven package org.fourthline.cling:cling-core