Описание
Mattermost version 2.10.0 and earlier fails to sanitize deeplink paths, which allows an attacker to perform CSRF attacks against the server.
Пакеты
Пакет | Статус | Версия исправления | Релиз | Тип |
---|---|---|---|---|
mattermost-server | itp | package |
EPSS
Процентиль: 52%
0.00286
Низкий
Связанные уязвимости
CVSS3: 7.1
nvd
больше 1 года назад
Mattermost version 2.10.0 and earlier fails to sanitize deeplink paths, which allows an attacker to perform CSRF attacks against the server.
CVSS3: 7.1
github
больше 1 года назад
Mattermost version 2.10.0 and earlier fails to sanitize deeplink paths, which allows an attacker to perform CSRF attacks against the server.
EPSS
Процентиль: 52%
0.00286
Низкий