Lucene search

K
osvGoogleOSV:GHSA-22C6-3H88-26M3
HistoryMay 24, 2022 - 5:11 p.m.

Ignite Realtime Openfire allows Cross-site Scripting

2022-05-2417:11:57
Google
osv.dev
9
ignite realtime
openfire
cross-site scripting
version 4.4.1
version 4.4.2
setup datasource standard
serverurl parameter

EPSS

0.001

Percentile

37.3%

Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp serverURL parameter. This issue was fixed in version 4.4.2.

EPSS

0.001

Percentile

37.3%

Related for OSV:GHSA-22C6-3H88-26M3