Vulnerabilities/

User Impersonation in converse.js

Severity:
Medium

Description

Versions of converse.js prior to 1.0.7 for 1.x or 2.0.5 for 2.x are vulnerable to User Impersonation. The package provides an incorrect implementation of XEP-0280: Message Carbons that allows a remote attacker to impersonate any user, including contacts, in the vulnerable application’s display.

Recommendation

Update the converse.js package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
converse.js
Anything's wrong? Let us know Last updated on January 09, 2023

This issue is available in SmartScanner Professional

See Pricing