CVE-2020-36956 | igniterealtime Openfire up to 4.6.0 Configuration path cross site scripting (Exploit 49229 / EDB-49229)
A vulnerability labeled as problematic has been found in igniterealtime Openfire up to 4.6.0. Affected by this issue is some unknown functionality of the component Configuration Handler. Such manipulation of the argument path leads to cross site scripting.
This vulnerability is documented as CVE-2020-36956. The attack can be executed remotely. Additionally, an exploit exists.