First published: Thu Feb 09 2017(Updated: )
An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks. This CVE is for Movim 0.8 - 0.10.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Movim Movim | =0.8 | |
Movim Movim | =0.8.1 | |
Movim Movim | =0.9 | |
Movim Movim | =0.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.