Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:3547
HistoryFeb 10, 2017 - 1:55 a.m.

Social Engineering Attack Via Impersonation

2017-02-1001:55:19
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9

EPSS

0.002

Percentile

65.4%

slixmpp and sleekxmpp are vulnerable to social engineering attacks via a loophole leading to impersonation. It happens due to a flaw in the implementation of XEP-0280: Message Carbons in multiple XMPP clients, allowing a malicious user to impersonate any user, including contacts in the vulnerable application’s display.