Show filters
898 Total Results
Displaying 251-260 of 898
Sort by:
Attacker Value
Unknown

CVE-2023-43754

Disclosure Date: November 27, 2023 (last updated February 25, 2025)
Mattermost fails to check whether the  “Allow users to view archived channels”  setting is enabled during permalink previews display, allowing members to view permalink previews of archived channels even if the “Allow users to view archived channels” setting is disabled. 
Attacker Value
Unknown

CVE-2023-40703

Disclosure Date: November 27, 2023 (last updated February 25, 2025)
Mattermost fails to properly limit the characters allowed in different fields of a block in Mattermost Boards allowing a attacker to consume excessive resources, possibly leading to Denial of Service, by patching the field of a block using a specially crafted string. 
Attacker Value
Unknown

CVE-2023-35075

Disclosure Date: November 27, 2023 (last updated February 25, 2025)
Mattermost fails to use  innerText / textContent when setting the channel name in the webapp during autocomplete, allowing an attacker to inject HTML to a victim's page by create a channel name that is valid HTML. No XSS is possible though. 
Attacker Value
Unknown

CVE-2023-47865

Disclosure Date: November 27, 2023 (last updated February 25, 2025)
Mattermost fails to check if hardened mode is enabled when overriding the username and/or the icon when posting a post. If settings allowed integrations to override the username and profile picture when posting, a member could also override the username and icon when making a post even if the Hardened Mode setting was enabled
Attacker Value
Unknown

CVE-2023-4595

Disclosure Date: November 23, 2023 (last updated February 25, 2025)
An information exposure vulnerability has been found, the exploitation of which could allow a remote user to retrieve sensitive information stored on the server such as credential files, configuration files, application files, etc., simply by appending any of the following parameters to the end of the URL: %00 %0a, %20, %2a, %a0, %aa, %c0 and %ca.
Attacker Value
Unknown

CVE-2023-4594

Disclosure Date: November 23, 2023 (last updated February 25, 2025)
Stored XSS vulnerability. This vulnerability could allow an attacker to store a malicious JavaScript payload via GET and POST methods on multiple parameters in the MailAdmin_dll.htm file.
Attacker Value
Unknown

CVE-2023-4593

Disclosure Date: November 23, 2023 (last updated February 25, 2025)
Path traversal vulnerability whose exploitation could allow an authenticated remote user to bypass SecurityManager's intended restrictions and list a parent directory via any filename, such as a multiple ..%2F value affecting the 'dodoc' parameter in the /MailAdmin_dll.htm file.
Attacker Value
Unknown

CVE-2023-47230

Disclosure Date: November 13, 2023 (last updated February 25, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Cimatti Consulting WordPress Contact Forms by Cimatti plugin <= 1.6.0 versions.
Attacker Value
Unknown

CVE-2023-5969

Disclosure Date: November 06, 2023 (last updated February 25, 2025)
Mattermost fails to properly sanitize the request to /api/v4/redirect_location allowing an attacker, sending a specially crafted request to /api/v4/redirect_location, to fill up the memory due to caching large items.
Attacker Value
Unknown

CVE-2023-5968

Disclosure Date: November 06, 2023 (last updated February 25, 2025)
Mattermost fails to properly sanitize the user object when updating the username, resulting in the password hash being included in the response body.