An issue in Ignite Realtime Openfire before 4.8.1 allows a remote attacker to escalate privileges via the admin.authorizedJIDs system property component.
https://www.igniterealtime.org/projects/openfire/
https://www.hackthebox.com/blog/openfire-cves-explained-CVE-2024-25420-CVE-2024-25421
https://igniterealtime.atlassian.net/browse/OF-2758
https://github.com/igniterealtime/Openfire/releases/tag/v4.8.1