PT-2017-16611 · Redsolution · Xabber
Published
2017-02-09
·
Updated
2020-01-22
·
CVE-2017-5606
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Xabber versions 1.0.30 through 1.0.74
Description
The issue is related to an incorrect implementation of XEP-0280: Message Carbons in the XMPP client, allowing a remote attacker to impersonate any user in the vulnerable application's display. This can lead to various kinds of social engineering attacks.
Recommendations
For Xabber versions 1.0.30 through 1.0.74, consider disabling the implementation of XEP-0280: Message Carbons until a proper fix is available.
Exploit
Fix
Origin Validation Error
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Xabber