Tigase XMPP Server Stanza Smuggling...

- AV AC AU C I A
发布: 2022-05-26
修订: 2025-04-13

Tigase XMPP server suffers from a security vulnerability due to not escaping double quote character when serializing parsed XML. This can be used to smuggle (or, if you prefer, inject) an arbitrary attacker-controlled stanza in the XMPP server's output stream. A malicious client can abuse this vulnerability to send arbitrary XMPP stanzas to another client (including the control stanzas that are only meant to be sent by the server).

0%
暂无可用Exp或PoC
当前有0条受影响产品信息