Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2pjr-m4w4-33wx

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.9

Описание

An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks. This CVE is for jappix 1.0.0 to 1.1.6.

An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks. This CVE is for jappix 1.0.0 to 1.1.6.

EPSS

Процентиль: 48%
0.00245
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 5.9
nvd
почти 9 лет назад

An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks. This CVE is for jappix 1.0.0 to 1.1.6.

CVSS3: 5.9
debian
почти 9 лет назад

An incorrect implementation of "XEP-0280: Message Carbons" in multiple ...

EPSS

Процентиль: 48%
0.00245
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-20