Home / os / blackberry

CoreDial sipXcom sipXopenfire 21.04 Remote Command Execution / Weak Permissions

Posted on 12 March 2023

CoreDial sipXcom sipXopenfire versions 21.04 and below suffer from XMPP message system command argument injection and insecure service file permissions that when chained together gives root.

 

TOP