{"id":"CVE-2017-5605","aliases":["GHSA-hq38-v658-g3wp"],"url":"https://o3.security/vulnerability/CVE-2017-5605","summary":"XMPP Clients User Impersonation Vulnerability in Movim Moxl","details":"An incorrect implementation of \"XEP-0280: Message Carbons\" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks. This CVE is for Movim 0.8 - 0.10.","published":"2017-02-09T20:59:00.497Z","modified":"2026-07-08T16:53:47.470732Z","cvss":{"score":5.9,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":3,"affectedPackages":[{"ecosystem":"Packagist","name":"movim/moxl","fixedVersion":null}],"fix":{"url":"https://github.com/movim/moxl/commit/838b0a42efc3b67cc17d63e25ae1d0ea849cd89b","label":"movim/moxl@838b0a4"},"references":[{"type":"WEB","url":"http://www.securityfocus.com/bid/96177"},{"type":"FIX","url":"https://github.com/movim/moxl/commit/838b0a42efc3b67cc17d63e25ae1d0ea849cd89b"},{"type":"EVIDENCE","url":"http://openwall.com/lists/oss-security/2017/02/09/29"},{"type":"EVIDENCE","url":"https://rt-solutions.de/en/2017/02/CVE-2017-5589_xmpp_carbons/"},{"type":"EVIDENCE","url":"https://rt-solutions.de/wp-content/uploads/2017/02/CVE-2017-5589_xmpp_carbons.pdf"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T16:53:47.470732Z"}}