An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks. This CVE is for Movim 0.8 - 0.10.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "0.8"
},
{
"introduced": "0"
},
{
"last_affected": "0.8.1"
},
{
"introduced": "0"
},
{
"last_affected": "0.9"
},
{
"introduced": "0"
},
{
"last_affected": "0.10"
}
]
}