Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5ffg-379q-g96f

Опубликовано: 18 дек. 2021
Источник: github
Github: Не прошло ревью

Описание

Mattermost 6.0 and earlier fails to sufficiently validate the email address during registration, which allows attackers to trick users into signing up using attacker-controlled email addresses via crafted invitation token.

Mattermost 6.0 and earlier fails to sufficiently validate the email address during registration, which allows attackers to trick users into signing up using attacker-controlled email addresses via crafted invitation token.

EPSS

Процентиль: 38%
0.00168
Низкий

Дефекты

CWE-754

Связанные уязвимости

CVSS3: 3.7
nvd
около 4 лет назад

Mattermost 6.0 and earlier fails to sufficiently validate the email address during registration, which allows attackers to trick users into signing up using attacker-controlled email addresses via crafted invitation token.

CVSS3: 3.7
debian
около 4 лет назад

Mattermost 6.0 and earlier fails to sufficiently validate the email ad ...

EPSS

Процентиль: 38%
0.00168
Низкий

Дефекты

CWE-754