PT-2017-16611 · Redsolution · Xabber
Publicado
2017-02-09
·
Atualizado
2020-01-22
·
CVE-2017-5606
CVSS v3.1
5.9
Média
| Vetor | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Xabber versions 1.0.30 through 1.0.74
Description
The issue is related to an incorrect implementation of XEP-0280: Message Carbons in the XMPP client, allowing a remote attacker to impersonate any user in the vulnerable application's display. This can lead to various kinds of social engineering attacks.
Recommendations
For Xabber versions 1.0.30 through 1.0.74, consider disabling the implementation of XEP-0280: Message Carbons until a proper fix is available.
Exploit
Correção
Origin Validation Error
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Xabber