Описание
Mattermost vulnerable to cross-site scripting (XSS)
Boards in Mattermost allows an attacker to upload a malicious SVG image file as an attachment to a card and share it using a direct link to the file.
Issue Identifier: MMSA-2023-00139
Пакеты
github.com/mattermost/mattermost-server/v6
>= 6.0.0, <= 6.7.2
7.1.6
github.com/mattermost/mattermost-server
>= 7.7.0, <= 7.7.1
7.7.2
github.com/mattermost/mattermost-server
>= 7.1.0, <= 7.1.5
7.1.6
github.com/mattermost/mattermost-server
= 7.8.0
7.8.1
github.com/mattermost/mattermost-server/v5
>= 5.0.0, <= 5.39.3
7.1.6
github.com/mattermost/mattermost-server/v6
>= 3.3.0, <= 4.10.10
7.1.6
Связанные уязвимости
Boards in Mattermost allows an attacker to upload a malicious SVG image file as an attachment to a card and share it using a direct link to the file.
Boards in Mattermost allows an attacker to upload a malicious SVG imag ...