Description
Ignite Realtime Openfire 4.6.0 has plugins/clientcontrol/spark-form.jsp Reflective XSS.
Remediation
References
https://discourse.igniterealtime.org/t/openfire-4-6-0-has-reflective-xss-vulnerabilities/89296
Related Vulnerabilities
CVE-2023-45135 Vulnerability in maven package org.xwiki.platform:xwiki-platform-web-templates
CVE-2020-10992 Vulnerability in maven package com.linkedin.azkaban:azkaban-common
CVE-2023-48219 Vulnerability in maven package org.webjars:tinymce
CVE-2022-38370 Vulnerability in maven package org.apache.iotdb:iotdb-grafana-connector
CVE-2012-0392 Vulnerability in maven package org.apache.struts.xwork:xwork-core