Ignite Realtime Openfire before 4.4.1 has reflected XSS via an LDAP setup test.
[
{
"id": "CVE-2019-15488-f8730e72",
"target": {
"file": "xmppserver/src/main/java/org/jivesoftware/openfire/spi/XMPPServerInfoImpl.java"
},
"digest": {
"line_hashes": [
"159326535391292090120439935024291710326",
"320810630339546509092423595118835811086",
"269151367449382371545130140467234556116",
"222517828649213961204851722210321250352"
],
"threshold": 0.9
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line",
"source": "https://github.com/igniterealtime/openfire/commit/5e5d9e58eb05764f50e5d2b03ee7416dab9bb6a1"
}
]