VYPR

Spark

by Igniterealtime

CVEs (1)

  • CVE-2020-12772HigMay 12, 2020
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in Ignite Realtime Spark 2.8.3 (and the ROAR plugin for it) on Windows. A chat message can include an IMG element with a SRC attribute referencing an external host's IP address. Upon access to this external host, the (NT)LM hashes of the user are sent…