PoC Index

CVE-2021-45968

HIGH 7.5EPSS 10.4%

An issue was discovered in xmppserver jar in the XMPP Server component of the JIve platform, as used in Pascom Cloud Phone System before 7.20.x (and in other products). An endpoint in the backend Tomcat server of the Pascom allows SSRF, a related issue to CVE-2019-18394.

CVSS v3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
10.38% chance of exploitation in the next 30 days, 95th percentile
Nuclei
high · CWE-918
Published
2022-03-18
Updated
2024-08-04

Proof-of-concept exploits (1)

Nuclei templates (1)

References

Related