Description
Ignite Realtime Openfire 4.6.0 has plugins/clientcontrol/spark-form.jsp Reflective XSS.
Remediation
References
https://discourse.igniterealtime.org/t/openfire-4-6-0-has-reflective-xss-vulnerabilities/89296
Related Vulnerabilities
CVE-2023-44487 Vulnerability in maven package org.apache.tomcat:tomcat-coyote
CVE-2023-46998 Vulnerability in maven package org.webjars.npm:bootbox.js
CVE-2021-23337 Vulnerability in npm package lodash
CVE-2020-7707 Vulnerability in maven package org.webjars.npm:property-expr
CVE-2023-39106 Vulnerability in maven package com.alibaba.nacos:nacos-spring-context