Описание
Mattermost 5.38 and earlier fails to sufficiently sanitize clipboard contents, which allows a user-assisted attacker to inject arbitrary web script in product deployments that explicitly disable the default CSP.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип | 
|---|---|---|---|---|
| mattermost-server | itp | package | 
EPSS
Процентиль: 53%
0.003
Низкий
Связанные уязвимости
CVSS3: 3.7
nvd
около 4 лет назад
Mattermost 5.38 and earlier fails to sufficiently sanitize clipboard contents, which allows a user-assisted attacker to inject arbitrary web script in product deployments that explicitly disable the default CSP.
EPSS
Процентиль: 53%
0.003
Низкий