First published: Thu Feb 09 2017(Updated: )
An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks. This CVE is for Movim 0.8 - 0.10.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Movim | =0.8 | |
Movim | =0.8.1 | |
Movim | =0.9 | |
Movim | =0.10 | |
=0.8 | ||
=0.8.1 | ||
=0.9 | ||
=0.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-5605 is considered a medium severity vulnerability due to the potential for social engineering attacks.
To mitigate CVE-2017-5605, upgrade Movim to the latest version beyond 0.10 which addresses this vulnerability.
CVE-2017-5605 affects Movim versions 0.8, 0.8.1, 0.9, and 0.10.
CVE-2017-5605 allows remote attackers to impersonate users in the application, facilitating various social engineering attacks.
While not detailed in the description, CVE-2017-5605's vulnerability can be exploited through crafted XMPP messages.