Описание
Mattermost fails to restrict which parameters' values it takes from the request during signup allowing an attacker to register users as inactive, thus blocking them from later accessing Mattermost without the system admin activating their accounts.
Ссылки
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 7.8.9 (исключая)Версия от 7.9.0 (включая) до 7.10.5 (исключая)
Одно из
cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
cpe:2.3:a:mattermost:mattermost_server:8.0.0:*:*:*:*:*:*:*
EPSS
Процентиль: 53%
0.00298
Низкий
4.3 Medium
CVSS3
8.2 High
CVSS3
Дефекты
CWE-74
CWE-74
Связанные уязвимости
CVSS3: 4.3
debian
больше 2 лет назад
Mattermost fails to restrict which parameters' values it takes from th ...
CVSS3: 4.3
github
больше 2 лет назад
Mattermost fails to restrict which parameters' values it takes from the request during signup allowing an attacker to register users as inactive, thus blocking them from later accessing Mattermost without the system admin activating their accounts.
EPSS
Процентиль: 53%
0.00298
Низкий
4.3 Medium
CVSS3
8.2 High
CVSS3
Дефекты
CWE-74
CWE-74