Show filters
229 Total Results
Displaying 81-90 of 229
Sort by:
Attacker Value
Unknown
CVE-2022-1384
Disclosure Date: April 19, 2022 (last updated February 23, 2025)
Mattermost version 6.4.x and earlier fails to properly check the plugin version when a plugin is installed from the Marketplace, which allows an authenticated and an authorized user to install and exploit an old plugin version from the Marketplace which might have known vulnerabilities.
0
Attacker Value
Unknown
CVE-2022-1337
Disclosure Date: April 13, 2022 (last updated February 23, 2025)
The image proxy component in Mattermost version 6.4.1 and earlier allocates memory for multiple copies of a proxied image, which allows an authenticated attacker to crash the server via links to very large image files.
0
Attacker Value
Unknown
CVE-2022-1332
Disclosure Date: April 13, 2022 (last updated February 23, 2025)
One of the API in Mattermost version 6.4.1 and earlier fails to properly protect the permissions, which allows the authenticated members with restricted custom admin role to bypass the restrictions and view the server logs and server config.json file contents.
0
Attacker Value
Unknown
CVE-2022-0904
Disclosure Date: March 10, 2022 (last updated February 23, 2025)
A stack overflow bug in the document extractor in Mattermost Server in versions up to and including 6.3.2 allows an attacker to crash the server via submitting a maliciously crafted Apple Pages document.
0
Attacker Value
Unknown
CVE-2022-0903
Disclosure Date: March 10, 2022 (last updated February 23, 2025)
A call stack overflow bug in the SAML login feature in Mattermost server in versions up to and including 6.3.2 allows an attacker to crash the server via submitting a maliciously crafted POST body.
0
Attacker Value
Unknown
CVE-2021-37863
Disclosure Date: December 17, 2021 (last updated February 23, 2025)
Mattermost 6.0 and earlier fails to sufficiently validate parameters during post creation, which allows authenticated attackers to cause a client-side crash of the web application via a maliciously crafted post.
0
Attacker Value
Unknown
CVE-2021-37862
Disclosure Date: December 17, 2021 (last updated February 23, 2025)
Mattermost 6.0 and earlier fails to sufficiently validate the email address during registration, which allows attackers to trick users into signing up using attacker-controlled email addresses via crafted invitation token.
0
Attacker Value
Unknown
CVE-2016-11077
Disclosure Date: June 19, 2020 (last updated February 21, 2025)
An issue was discovered in Mattermost Server before 3.0.0. It has a superfluous API in which the System Admin can change the account name and e-mail address of an LDAP account.
0
Attacker Value
Unknown
CVE-2016-11065
Disclosure Date: June 19, 2020 (last updated February 21, 2025)
An issue was discovered in Mattermost Server before 3.3.0. An attacker could use the WebSocket feature to send pop-up messages to users or change a post's appearance.
0
Attacker Value
Unknown
CVE-2016-11074
Disclosure Date: June 19, 2020 (last updated February 21, 2025)
An issue was discovered in Mattermost Server before 3.0.0. A password-reset link could be reused.
0