Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown
CVE-2023-1777
Disclosure Date: March 31, 2023 (last updated November 08, 2023)
Mattermost allows an attacker to request a preview of an existing message when creating a new message via the createPost API call, disclosing the contents of the linked message.
0
Attacker Value
Unknown
CVE-2023-1776
Disclosure Date: March 31, 2023 (last updated November 08, 2023)
Boards in Mattermost allows an attacker to upload a malicious SVG image file as an attachment to a card and share it using a direct link to the file.
0
Attacker Value
Unknown
CVE-2023-1775
Disclosure Date: March 31, 2023 (last updated November 08, 2023)
When running in a High Availability configuration, Mattermost fails to sanitize some of the user_updated and post_deleted events broadcast to all users, leading to disclosure of sensitive information to some of the users with currently connected Websocket clients.
0
Attacker Value
Unknown
CVE-2023-1774
Disclosure Date: March 31, 2023 (last updated November 08, 2023)
When processing an email invite to a private channel on a team, Mattermost fails to validate the inviter's permission to that channel, allowing an attacker to invite themselves to a private channel.
0