Ignite Realtime Openfire through 4.4.2 is vulnerable to local file inclusion via PluginServlet.java. It does not ensure that retrieved files are located under the Openfire home directory.
id: CVE-2019-18393
info:
name: Ignite Realtime Openfire <4.42 - Local File Inclusion
author: pi
...