Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-22fj-xvpx-pqm9

Опубликовано: 29 дек. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.1

Описание

Mattermost version 2.10.0 and earlier fails to sanitize deeplink paths, which allows an attacker to perform CSRF attacks against the server.

Mattermost version 2.10.0 and earlier fails to sanitize deeplink paths, which allows an attacker to perform CSRF attacks against the server.

EPSS

Процентиль: 52%
0.00286
Низкий

7.1 High

CVSS3

Дефекты

CWE-22
CWE-74

Связанные уязвимости

CVSS3: 7.1
nvd
больше 1 года назад

Mattermost version 2.10.0 and earlier fails to sanitize deeplink paths, which allows an attacker to perform CSRF attacks against the server.

CVSS3: 7.1
debian
больше 1 года назад

Mattermost version 2.10.0 and earlier fails to sanitize deeplink paths ...

EPSS

Процентиль: 52%
0.00286
Низкий

7.1 High

CVSS3

Дефекты

CWE-22
CWE-74