CVE-2012-4670

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
25/08/2012
Last modified:
11/04/2025

Description

Tigase XMPP Server before 5.1.0 does not verify that a request was made for an XMPP Server Dialback response, which allows remote XMPP servers to spoof domains via a (1) Verify Response or (2) Authorization Response.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:tigase:tigase_xmpp_server:*:beta2:*:*:*:*:*:* 5.1.0 (including)