Логотип exploitDog
product: "mattermost"
Консоль
Логотип exploitDog

exploitDog

product: "mattermost"

Количество 232

Количество 232

debian логотип

CVE-2023-5969

больше 1 года назад

Mattermost fails to properly sanitize the request to/api/v4/redirect_l ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2023-5968

больше 1 года назад

Mattermost fails to properly sanitize the user object when updating the username, resulting in the password hash being included in the response body. 

CVSS3: 4.9
EPSS: Низкий
debian логотип

CVE-2023-5968

больше 1 года назад

Mattermost fails to properly sanitize the user object when updating th ...

CVSS3: 4.9
EPSS: Низкий
nvd логотип

CVE-2023-5967

больше 1 года назад

Mattermost fails to properly validate requests to the Calls plugin, allowing an attacker sending a request without a User Agent header to cause a panic and crash the Calls plugin

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2023-5967

больше 1 года назад

Mattermost fails to properly validate requests to the Calls plugin, al ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2023-5522

больше 1 года назад

Mattermost Mobile fails to limit the maximum number of Markdown elements in a post allowing an attacker to send a post with hundreds of emojis to a channel and freeze the mobile app of users when viewing that particular channel. 

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2023-5196

больше 1 года назад

Mattermost fails to enforce character limits in all possible notification props allowing an attacker to send a really long value for a notification_prop resulting in the server consuming an abnormal quantity of computing resources and possibly becoming temporarily unavailable for its users.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2023-5196

больше 1 года назад

Mattermost fails to enforce character limits in all possible notificat ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2023-5195

больше 1 года назад

Mattermost fails to properly validate the permissions when soft deleting a team allowing a team member to soft delete other teams that they are not part of

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2023-5195

больше 1 года назад

Mattermost fails to properly validate the permissions when soft deleti ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2023-5194

больше 1 года назад

Mattermost fails to properly validate permissions when demoting and deactivating a user allowing for a system/user manager to demote / deactivate another manager

CVSS3: 2.7
EPSS: Низкий
debian логотип

CVE-2023-5194

больше 1 года назад

Mattermost fails to properly validate permissions when demoting and de ...

CVSS3: 2.7
EPSS: Низкий
nvd логотип

CVE-2023-5193

больше 1 года назад

Mattermost fails to properly check permissions when retrieving a post allowing for a System Role with the permission to manage channels to read the posts of a DM conversation.

CVSS3: 4.9
EPSS: Низкий
debian логотип

CVE-2023-5193

больше 1 года назад

Mattermost fails to properly check permissions when retrieving a post ...

CVSS3: 4.9
EPSS: Низкий
nvd логотип

CVE-2023-5160

больше 1 года назад

Mattermost fails to check the Show Full Name option at the /api/v4/teams/TEAM_ID/top/team_members endpoint allowing a member to get the full name of another user even if the Show Full Name option was disabled

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2023-5160

больше 1 года назад

Mattermost fails to check the Show Full Name option at the /api/v4/tea ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2023-5159

больше 1 года назад

Mattermost fails to properly verify the permissions when managing/updating a bot allowing a User Manager role with user edit permissions to manage/update bots.

CVSS3: 3.8
EPSS: Низкий
debian логотип

CVE-2023-5159

больше 1 года назад

Mattermost fails to properly verify the permissions when managing/upda ...

CVSS3: 3.8
EPSS: Низкий
nvd логотип

CVE-2023-48369

больше 1 года назад

Mattermost fails to limit the log size of server logs allowing an attacker sending specially crafted requests to different endpoints to potentially overflow the log.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2023-48369

больше 1 года назад

Mattermost fails to limit the log size of server logs allowing an atta ...

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2023-5969

Mattermost fails to properly sanitize the request to/api/v4/redirect_l ...

CVSS3: 5.3
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2023-5968

Mattermost fails to properly sanitize the user object when updating the username, resulting in the password hash being included in the response body. 

CVSS3: 4.9
0%
Низкий
больше 1 года назад
debian логотип
CVE-2023-5968

Mattermost fails to properly sanitize the user object when updating th ...

CVSS3: 4.9
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2023-5967

Mattermost fails to properly validate requests to the Calls plugin, allowing an attacker sending a request without a User Agent header to cause a panic and crash the Calls plugin

CVSS3: 4.3
0%
Низкий
больше 1 года назад
debian логотип
CVE-2023-5967

Mattermost fails to properly validate requests to the Calls plugin, al ...

CVSS3: 4.3
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2023-5522

Mattermost Mobile fails to limit the maximum number of Markdown elements in a post allowing an attacker to send a post with hundreds of emojis to a channel and freeze the mobile app of users when viewing that particular channel. 

CVSS3: 4.3
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2023-5196

Mattermost fails to enforce character limits in all possible notification props allowing an attacker to send a really long value for a notification_prop resulting in the server consuming an abnormal quantity of computing resources and possibly becoming temporarily unavailable for its users.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
debian логотип
CVE-2023-5196

Mattermost fails to enforce character limits in all possible notificat ...

CVSS3: 6.5
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2023-5195

Mattermost fails to properly validate the permissions when soft deleting a team allowing a team member to soft delete other teams that they are not part of

CVSS3: 6.5
0%
Низкий
больше 1 года назад
debian логотип
CVE-2023-5195

Mattermost fails to properly validate the permissions when soft deleti ...

CVSS3: 6.5
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2023-5194

Mattermost fails to properly validate permissions when demoting and deactivating a user allowing for a system/user manager to demote / deactivate another manager

CVSS3: 2.7
0%
Низкий
больше 1 года назад
debian логотип
CVE-2023-5194

Mattermost fails to properly validate permissions when demoting and de ...

CVSS3: 2.7
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2023-5193

Mattermost fails to properly check permissions when retrieving a post allowing for a System Role with the permission to manage channels to read the posts of a DM conversation.

CVSS3: 4.9
0%
Низкий
больше 1 года назад
debian логотип
CVE-2023-5193

Mattermost fails to properly check permissions when retrieving a post ...

CVSS3: 4.9
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2023-5160

Mattermost fails to check the Show Full Name option at the /api/v4/teams/TEAM_ID/top/team_members endpoint allowing a member to get the full name of another user even if the Show Full Name option was disabled

CVSS3: 4.3
0%
Низкий
больше 1 года назад
debian логотип
CVE-2023-5160

Mattermost fails to check the Show Full Name option at the /api/v4/tea ...

CVSS3: 4.3
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2023-5159

Mattermost fails to properly verify the permissions when managing/updating a bot allowing a User Manager role with user edit permissions to manage/update bots.

CVSS3: 3.8
0%
Низкий
больше 1 года назад
debian логотип
CVE-2023-5159

Mattermost fails to properly verify the permissions when managing/upda ...

CVSS3: 3.8
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2023-48369

Mattermost fails to limit the log size of server logs allowing an attacker sending specially crafted requests to different endpoints to potentially overflow the log.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
debian логотип
CVE-2023-48369

Mattermost fails to limit the log size of server logs allowing an atta ...

CVSS3: 4.3
0%
Низкий
больше 1 года назад

Уязвимостей на страницу