Field Assessment
AI analysis pending.
CVE
CVE-2016-0756
Severity
MEDIUM
CVSS
5.3
EPSS
2.05%
Original Filing — NVD Description
The generate_dialback function in the mod_dialback module in Prosody before 0.9.10 does not properly separate fields when generating dialback keys, which allows remote attackers to spoof XMPP network domains via a crafted stream id and domain name that is included in the target domain as a suffix.