Show filters
229 Total Results
Displaying 111-120 of 229
Sort by:
Attacker Value
Unknown
CVE-2017-18921
Disclosure Date: June 19, 2020 (last updated February 21, 2025)
An issue was discovered in Mattermost Server before 3.6.0 and 3.5.2. XSS can occur via a link on an error page.
0
Attacker Value
Unknown
CVE-2017-18919
Disclosure Date: June 19, 2020 (last updated February 21, 2025)
An issue was discovered in Mattermost Server before 3.7.0 and 3.6.3. Attackers can use the API for unauthenticated team creation.
0
Attacker Value
Unknown
CVE-2017-18917
Disclosure Date: June 19, 2020 (last updated February 21, 2025)
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. Weak hashing was used for e-mail invitations, OAuth, and e-mail verification tokens.
0
Attacker Value
Unknown
CVE-2016-11068
Disclosure Date: June 19, 2020 (last updated February 21, 2025)
An issue was discovered in Mattermost Server before 3.2.0. Attackers could read LDAP fields via injection.
0
Attacker Value
Unknown
CVE-2016-11075
Disclosure Date: June 19, 2020 (last updated February 21, 2025)
An issue was discovered in Mattermost Server before 3.0.0. It allows attackers to obtain sensitive information about team URLs via an API.
0
Attacker Value
Unknown
CVE-2016-11062
Disclosure Date: June 19, 2020 (last updated February 21, 2025)
An issue was discovered in Mattermost Server before 3.5.1. E-mail address verification can be bypassed.
0
Attacker Value
Unknown
CVE-2017-18914
Disclosure Date: June 19, 2020 (last updated February 21, 2025)
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. An external link can occur on an error page even if it is not on an allowlist.
0
Attacker Value
Unknown
CVE-2017-18905
Disclosure Date: June 19, 2020 (last updated February 21, 2025)
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2, when used as an OAuth 2.0 service provider, Session invalidation was mishandled.
0
Attacker Value
Unknown
CVE-2016-11063
Disclosure Date: June 19, 2020 (last updated February 21, 2025)
An issue was discovered in Mattermost Server before 3.5.1. XSS can occur via file preview.
0
Attacker Value
Unknown
CVE-2016-11073
Disclosure Date: June 19, 2020 (last updated February 21, 2025)
An issue was discovered in Mattermost Server before 3.0.0. It allows XSS via a Legal or Support setting.
0