VYPR
Critical severity9.8NVD Advisory· Published Feb 1, 2021· Updated Jun 17, 2026

CVE-2020-26547

CVE-2020-26547

Description

Monal before 4.9 does not implement proper sender verification on MAM and Message Carbon (XEP-0280) results. This allows a remote attacker (able to send stanzas to a victim) to inject arbitrary messages into the local history, with full control over the sender and receiver displayed to the victim.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Monal/Monal3 versions
    cpe:2.3:a:monal:monal:*:*:*:*:*:iphone_os:*:*+ 2 more
    • cpe:2.3:a:monal:monal:*:*:*:*:*:iphone_os:*:*range: <4.9
    • (no CPE)
    • (no CPE)range: <4.9

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.