Description
Ignite Realtime Openfire 4.6.0 has plugins/clientcontrol/spark-form.jsp Reflective XSS.
Remediation
References
https://discourse.igniterealtime.org/t/openfire-4-6-0-has-reflective-xss-vulnerabilities/89296
Related Vulnerabilities
CVE-2023-46115 Vulnerability in npm package @tauri-apps/cli
CVE-2023-24057 Vulnerability in maven package ca.uhn.hapi.fhir:org.hl7.fhir.r5
CVE-2023-30363 Vulnerability in npm package vconsole
CVE-2023-26134 Vulnerability in npm package git-commit-info
CVE-2021-21345 Vulnerability in maven package com.thoughtworks.xstream:xstream