Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-37860

Опубликовано: 22 сент. 2021
Источник: debian
EPSS Низкий

Описание

Mattermost 5.38 and earlier fails to sufficiently sanitize clipboard contents, which allows a user-assisted attacker to inject arbitrary web script in product deployments that explicitly disable the default CSP.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mattermost-serveritppackage

EPSS

Процентиль: 57%
0.00355
Низкий

Связанные уязвимости

CVSS3: 3.7
nvd
больше 3 лет назад

Mattermost 5.38 and earlier fails to sufficiently sanitize clipboard contents, which allows a user-assisted attacker to inject arbitrary web script in product deployments that explicitly disable the default CSP.

CVSS3: 6.1
github
больше 3 лет назад

Cross-site Scripting in Mattermost

EPSS

Процентиль: 57%
0.00355
Низкий