Description
Ignite Realtime Openfire 4.6.0 has plugins/dbaccess/db-access.jsp sql Stored XSS.
Remediation
References
https://www.exploit-db.com/exploits/49235
Related Vulnerabilities
CVE-2020-26938 Vulnerability in npm package oauth2-server
CVE-2021-25945 Vulnerability in npm package js-extend
CVE-2020-11023 Vulnerability in maven package org.webjars.bowergithub.jquery:jquery
CVE-2020-14967 Vulnerability in maven package org.webjars.bower:jsrsasign
CVE-2019-17570 Vulnerability in maven package org.apache.xmlrpc:xmlrpc-client