Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hv5f-73mr-7vvj

Опубликовано: 23 сент. 2021
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

Cross-site Scripting in Mattermost

Mattermost 5.38 and earlier fails to sufficiently sanitize clipboard contents, which allows a user-assisted attacker to inject arbitrary web script in product deployments that explicitly disable the default CSP.

Пакеты

Наименование

github.com/mattermost/mattermost-server/v5

go
Затронутые версииВерсия исправления

< 5.39.0

5.39.0

EPSS

Процентиль: 57%
0.00355
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 3.7
nvd
почти 4 года назад

Mattermost 5.38 and earlier fails to sufficiently sanitize clipboard contents, which allows a user-assisted attacker to inject arbitrary web script in product deployments that explicitly disable the default CSP.

CVSS3: 3.7
debian
почти 4 года назад

Mattermost 5.38 and earlier fails to sufficiently sanitize clipboard c ...

EPSS

Процентиль: 57%
0.00355
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79