CVE-2019-15488
Description
Openfire before 4.4.1 contains a reflected XSS vulnerability in the LDAP setup test page, allowing an attacker to inject arbitrary web script.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Openfire before 4.4.1 contains a reflected XSS vulnerability in the LDAP setup test page, allowing an attacker to inject arbitrary web script.
Vulnerability
Description
Ignite Realtime Openfire, an XMPP server, versions prior to 4.4.1 are vulnerable to a reflected cross-site scripting (XSS) issue in the LDAP setup test page [3]. The testing page, which checks whether a particular user configured to be an Openfire admin can be retrieved from LDAP, did not properly sanitize user-supplied input [4]. This allowed an attacker to inject malicious scripts that would be reflected back to the user's browser. The commit that fixes the issue is in pull request #1441 [4].
Attack
Vector
An attacker could exploit this vulnerability by crafting a malicious URL containing a payload and sending it to an authenticated administrator. The XSS is triggered when the admin accesses the LDAP setup test page with the crafted input. No special privileges beyond standard web access to the admin console are required for the attacker to craft the URL, but the victim must be an authenticated admin for the XSS to execute within the admin session context [1][4].
Impact
If successfully exploited, the attacker could execute arbitrary JavaScript in the context of the administrator's browser. This could lead to session hijacking, defacement of the admin interface, or redirection to malicious sites. The impact is limited to the admin session, but could potentially allow further compromise of the Openfire server if the admin's session is stolen or if malicious actions are performed on behalf of the admin [3][4].
Mitigation
Users should upgrade to Openfire version 4.4.1 or later to remediate this vulnerability [3]. The fix is available in the commit comparing cd0a573...5e5d9e5 on GitHub [1]. No workarounds are mentioned in available references, making an upgrade the recommended course of action.
AI Insight generated on May 22, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.igniterealtime.openfire:xmppserverMaven | < 4.4.1 | 4.4.1 |
Affected products
2- Ignite Realtime/Openfiredescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- github.com/advisories/GHSA-5qfv-rr79-chx5ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-15488ghsaADVISORY
- github.com/igniterealtime/Openfire/compare/cd0a573...5e5d9e5ghsax_refsource_MISCWEB
- github.com/igniterealtime/Openfire/pull/1441ghsax_refsource_MISCWEB
News mentions
0No linked articles in our index yet.