Опубликовано: 29 дек. 2023
Источник: github
Github: Прошло ревью
CVSS4: 2.1
CVSS3: 3.7
Описание
Mattermost Cross-site Scripting vulnerability
Mattermost version 8.1.6 and earlier fails to sanitize channel mention data in posts, which allows an attacker to inject markup in the web client.
Пакеты
Наименование
github.com/mattermost/mattermost/server/v8
go
Затронутые версииВерсия исправления
< 8.1.7
8.1.7
Связанные уязвимости
CVSS3: 3.7
nvd
около 2 лет назад
Mattermost version 8.1.6 and earlier fails to sanitize channel mention data in posts, which allows an attacker to inject markup in the web client.
CVSS3: 3.7
debian
около 2 лет назад
Mattermost version 8.1.6 and earlier fails to sanitize channel mention ...