Vulnerability Details CVE-2020-26547
Monal before 4.9 does not implement proper sender verification on MAM and Message Carbon (XEP-0280) results. This allows a remote attacker (able to send stanzas to a victim) to inject arbitrary messages into the local history, with full control over the sender and receiver displayed to the victim.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 43.2%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 5.0
Products affected by CVE-2020-26547
-
-
cpe:2.3:a:monal:monal:3.1
-
cpe:2.3:a:monal:monal:3.2
-
cpe:2.3:a:monal:monal:3.3
-
cpe:2.3:a:monal:monal:3.4
-
cpe:2.3:a:monal:monal:3.5
-
cpe:2.3:a:monal:monal:3.6
-
cpe:2.3:a:monal:monal:3.7
-
cpe:2.3:a:monal:monal:3.8
-
cpe:2.3:a:monal:monal:3.8.1
-
cpe:2.3:a:monal:monal:3.8.3
-
cpe:2.3:a:monal:monal:4.0
-
cpe:2.3:a:monal:monal:4.1
-
cpe:2.3:a:monal:monal:4.2
-
cpe:2.3:a:monal:monal:4.2.1
-
cpe:2.3:a:monal:monal:4.2.2
-
cpe:2.3:a:monal:monal:4.2.3
-
cpe:2.3:a:monal:monal:4.3
-
cpe:2.3:a:monal:monal:4.4
-
cpe:2.3:a:monal:monal:4.5
-
cpe:2.3:a:monal:monal:4.6
-
cpe:2.3:a:monal:monal:4.7
-
cpe:2.3:a:monal:monal:4.8