Описание
Mattermost Confluence plugin version <1.7.0 fails to properly escape user-controlled display names in HTML template rendering which allows authenticated Confluence users with malicious display names to execute arbitrary JavaScript in victim browsers via sending a specially crafted OAuth2 connection link that, when visited, renders the attacker's display name without proper sanitization. Mattermost Advisory ID: MMSA-2025-00557
EPSS
Процентиль: 1%
0.0001
Низкий
7.7 High
CVSS3
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 7.7
github
3 дня назад
Mattermost Confluence plugin doesn't properly escape user-controlled display names in HTML template rendering
EPSS
Процентиль: 1%
0.0001
Низкий
7.7 High
CVSS3
Дефекты
CWE-79