Vulnerabilities
Vulnerable Software
Prosody:  >> Prosody  >> 0.11.9  Security Vulnerabilities
It was discovered that an internal Prosody library to load XML based on libexpat does not properly restrict the XML features allowed in parsed XML data. Given suitable attacker input, this results in expansion of recursive entity references from DTDs (CWE-776). In addition, depending on the libexpat version used, it may also allow injections using XML External Entity References (CWE-611).
CVSS Score
7.5
EPSS Score
0.001
Published
2022-08-26
muc.lib.lua in Prosody 0.11.0 through 0.11.9 allows remote attackers to obtain sensitive information (list of admins, members, owners, and banned entities of a Multi-User chat room) in some common configurations.
CVSS Score
7.5
EPSS Score
0.007
Published
2021-07-30


Contact Us

Shodan ® - All rights reserved