📦

citadel

Vendor: citadel

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 0 Remote Access
Total CVEs 4 Total Indexed
Avg. EPSS 1.17% Exploit Prob.
Latest CVE CVE-2023-44272 Oct 04

Security Vulnerability Index

Page 1 / 1
5.4 CVSS

A cross-site scripting vulnerability exists in Citadel versions prior to 994. When a malicious user sends an instant message with some JavaScript code, the script may be executed on the web browser of the victim user.

EPSS: 0.44%
5.7 CVSS

The embedded neutralization of Script-Related HTML Tag, was by-passed in the case of some extra conditions.

EPSS: 0.41%
5.0 CVSS

modules/xmpp/serv_xmpp.c in Citadel 7.86 and earlier does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.

EPSS: 2.66%