Reflected XSS Vulnerability in Ignite Realtime Openfire Product
CVE-2019-15488
6.1MEDIUM
What is CVE-2019-15488?
Ignite Realtime's Openfire prior to version 4.4.1 is vulnerable to reflected Cross-Site Scripting (XSS) attacks via its LDAP setup test feature. This vulnerability allows an attacker to inject malicious scripts into web pages, which can be executed in the context of unsuspecting users. When these users interact with the affected feature, their browsers may unknowingly execute harmful scripts, potentially leading to unauthorized actions or data disclosure.
