Description
Ignite Realtime Openfire 4.6.0 has plugins/clientcontrol/spark-form.jsp Reflective XSS.
Remediation
References
https://discourse.igniterealtime.org/t/openfire-4-6-0-has-reflective-xss-vulnerabilities/89296
Related Vulnerabilities
CVE-2022-36083 Vulnerability in maven package org.webjars.npm:jose
CVE-2023-34616 Vulnerability in maven package com.progsbase.libraries:json
CVE-2023-50728 Vulnerability in npm package @octokit/webhooks
CVE-2023-49093 Vulnerability in maven package org.htmlunit:htmlunit
CVE-2020-7679 Vulnerability in maven package org.webjars.bower:casperjs