Lucene search

K
osvGoogleOSV:GHSA-WX2W-8PQW-VP4G
HistoryMay 24, 2022 - 5:11 p.m.

Ignite Realtime Openfire allows Cross-site Scripting

2022-05-2417:11:49
Google
osv.dev
9
ignite realtime
openfire
cross-site scripting
xss
version 4.4.2
security issue

EPSS

0.001

Percentile

37.3%

Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp username parameter. This issue was fixed in version 4.4.2.

EPSS

0.001

Percentile

37.3%

Related for OSV:GHSA-WX2W-8PQW-VP4G