Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-65h8-5q72-mrp3

Опубликовано: 25 авг. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

Mattermost fails to restrict which parameters' values it takes from the request during signup allowing an attacker to register users as inactive, thus blocking them from later accessing Mattermost without the system admin activating their accounts.

Mattermost fails to restrict which parameters' values it takes from the request during signup allowing an attacker to register users as inactive, thus blocking them from later accessing Mattermost without the system admin activating their accounts.

EPSS

Процентиль: 53%
0.00298
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 4.3
nvd
больше 2 лет назад

Mattermost fails to restrict which parameters' values it takes from the request during signup allowing an attacker to register users as inactive, thus blocking them from later accessing Mattermost without the system admin activating their accounts.

CVSS3: 4.3
debian
больше 2 лет назад

Mattermost fails to restrict which parameters' values it takes from th ...

EPSS

Процентиль: 53%
0.00298
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-74