Show filters
229 Total Results
Displaying 81-90 of 229
Sort by:
Attacker Value
Unknown

CVE-2022-1384

Disclosure Date: April 19, 2022 (last updated February 23, 2025)
Mattermost version 6.4.x and earlier fails to properly check the plugin version when a plugin is installed from the Marketplace, which allows an authenticated and an authorized user to install and exploit an old plugin version from the Marketplace which might have known vulnerabilities.
Attacker Value
Unknown

CVE-2022-1337

Disclosure Date: April 13, 2022 (last updated February 23, 2025)
The image proxy component in Mattermost version 6.4.1 and earlier allocates memory for multiple copies of a proxied image, which allows an authenticated attacker to crash the server via links to very large image files.
Attacker Value
Unknown

CVE-2022-1332

Disclosure Date: April 13, 2022 (last updated February 23, 2025)
One of the API in Mattermost version 6.4.1 and earlier fails to properly protect the permissions, which allows the authenticated members with restricted custom admin role to bypass the restrictions and view the server logs and server config.json file contents.
Attacker Value
Unknown

CVE-2022-0904

Disclosure Date: March 10, 2022 (last updated February 23, 2025)
A stack overflow bug in the document extractor in Mattermost Server in versions up to and including 6.3.2 allows an attacker to crash the server via submitting a maliciously crafted Apple Pages document.
Attacker Value
Unknown

CVE-2022-0903

Disclosure Date: March 10, 2022 (last updated February 23, 2025)
A call stack overflow bug in the SAML login feature in Mattermost server in versions up to and including 6.3.2 allows an attacker to crash the server via submitting a maliciously crafted POST body.
Attacker Value
Unknown

CVE-2021-37863

Disclosure Date: December 17, 2021 (last updated February 23, 2025)
Mattermost 6.0 and earlier fails to sufficiently validate parameters during post creation, which allows authenticated attackers to cause a client-side crash of the web application via a maliciously crafted post.
Attacker Value
Unknown

CVE-2021-37862

Disclosure Date: December 17, 2021 (last updated February 23, 2025)
Mattermost 6.0 and earlier fails to sufficiently validate the email address during registration, which allows attackers to trick users into signing up using attacker-controlled email addresses via crafted invitation token.
Attacker Value
Unknown

CVE-2016-11077

Disclosure Date: June 19, 2020 (last updated February 21, 2025)
An issue was discovered in Mattermost Server before 3.0.0. It has a superfluous API in which the System Admin can change the account name and e-mail address of an LDAP account.
Attacker Value
Unknown

CVE-2016-11065

Disclosure Date: June 19, 2020 (last updated February 21, 2025)
An issue was discovered in Mattermost Server before 3.3.0. An attacker could use the WebSocket feature to send pop-up messages to users or change a post's appearance.
Attacker Value
Unknown

CVE-2016-11074

Disclosure Date: June 19, 2020 (last updated February 21, 2025)
An issue was discovered in Mattermost Server before 3.0.0. A password-reset link could be reused.