Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rf7j-w28r-v7m8

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Monal before 4.9 does not implement proper sender verification on MAM and Message Carbon (XEP-0280) results. This allows a remote attacker (able to send stanzas to a victim) to inject arbitrary messages into the local history, with full control over the sender and receiver displayed to the victim.

Monal before 4.9 does not implement proper sender verification on MAM and Message Carbon (XEP-0280) results. This allows a remote attacker (able to send stanzas to a victim) to inject arbitrary messages into the local history, with full control over the sender and receiver displayed to the victim.

EPSS

Процентиль: 43%
0.00207
Низкий

Дефекты

CWE-345

Связанные уязвимости

CVSS3: 9.8
nvd
около 5 лет назад

Monal before 4.9 does not implement proper sender verification on MAM and Message Carbon (XEP-0280) results. This allows a remote attacker (able to send stanzas to a victim) to inject arbitrary messages into the local history, with full control over the sender and receiver displayed to the victim.

EPSS

Процентиль: 43%
0.00207
Низкий

Дефекты

CWE-345