CVE-2021-45968
HIGH NUCLEIXMPP Server <7.20.x - SSRF
Title source: llmDescription
An issue was discovered in xmppserver jar in the XMPP Server component of the JIve platform, as used in Pascom Cloud Phone System before 7.20.x (and in other products). An endpoint in the backend Tomcat server of the Pascom allows SSRF, a related issue to CVE-2019-18394.
Nuclei Templates (1)
Pascom CPS - Local File Inclusion
HIGHby dwisiswant0
References (5)
Scores
CVSS v3
7.5
EPSS
0.8683
EPSS Percentile
99.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-918
Status
published
Products (2)
jivesoftware/jive
pascom/cloud_phone_system
< 7.19
Published
Mar 18, 2022
Tracked Since
Feb 18, 2026