Логотип exploitDog
bind:CVE-2020-26547
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-26547

Количество 2

Количество 2

nvd логотип

CVE-2020-26547

около 5 лет назад

Monal before 4.9 does not implement proper sender verification on MAM and Message Carbon (XEP-0280) results. This allows a remote attacker (able to send stanzas to a victim) to inject arbitrary messages into the local history, with full control over the sender and receiver displayed to the victim.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-rf7j-w28r-v7m8

больше 3 лет назад

Monal before 4.9 does not implement proper sender verification on MAM and Message Carbon (XEP-0280) results. This allows a remote attacker (able to send stanzas to a victim) to inject arbitrary messages into the local history, with full control over the sender and receiver displayed to the victim.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-26547

Monal before 4.9 does not implement proper sender verification on MAM and Message Carbon (XEP-0280) results. This allows a remote attacker (able to send stanzas to a victim) to inject arbitrary messages into the local history, with full control over the sender and receiver displayed to the victim.

CVSS3: 9.8
0%
Низкий
около 5 лет назад
github логотип
GHSA-rf7j-w28r-v7m8

Monal before 4.9 does not implement proper sender verification on MAM and Message Carbon (XEP-0280) results. This allows a remote attacker (able to send stanzas to a victim) to inject arbitrary messages into the local history, with full control over the sender and receiver displayed to the victim.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу