Описание
An issue was discovered in Mattermost Server before 2.2.0. It allows XSS because it configures files to be opened in a browser window.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| mattermost-server | itp | package |
Связанные уязвимости
CVSS3: 6.1
nvd
больше 5 лет назад
An issue was discovered in Mattermost Server before 2.2.0. It allows XSS because it configures files to be opened in a browser window.
CVSS3: 6.1
github
больше 3 лет назад
Mattermost Server: Files may be rendered inline instead of downloaded, allowing script execution