Vulnerabilities
Vulnerable Software
Mattermost:  >> Mattermost  >> 6.2.3  Security Vulnerabilities
Mattermost 6.3.0 and earlier fails to properly sanitize the HTML content in the email invitation sent to guest users, which allows registered users with special permissions to invite guest users to inject unescaped HTML content in the email invitations.
CVSS Score
2.0
EPSS Score
0.002
Published
2022-03-18
One of the API in Mattermost version 6.3.0 and earlier fails to properly protect the permissions, which allows the system administrators to combine the two distinct privileges/capabilities in a way that allows them to override certain restricted configurations like EnableUploads.
CVSS Score
3.3
EPSS Score
0.001
Published
2022-03-18
Mattermost 6.3.0 and earlier fails to protect email addresses of the creator of the team via one of the APIs, which allows authenticated team members to access this information resulting in sensitive & private information disclosure.
CVSS Score
4.3
EPSS Score
0.004
Published
2022-02-21


Contact Us

Shodan ® - All rights reserved