Vulnerabilities
Vulnerable Software
Mattermost 6.0 and earlier fails to sufficiently validate parameters during post creation, which allows authenticated attackers to cause a client-side crash of the web application via a maliciously crafted post.
CVSS Score
3.5
EPSS Score
0.008
Published
2021-12-17
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. Knowledge of a session ID allows revoking another user's session.
CVSS Score
4.3
EPSS Score
0.008
Published
2020-06-19
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS could occur via the author_link field of a Slack attachment.
CVSS Score
6.1
EPSS Score
0.007
Published
2020-06-19
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS could occur via the title_link field of a Slack attachment.
CVSS Score
6.1
EPSS Score
0.007
Published
2020-06-19
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS could occur via a goto_location response to a slash command.
CVSS Score
6.1
EPSS Score
0.007
Published
2020-06-19
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS can occur via OpenGraph data.
CVSS Score
6.1
EPSS Score
0.007
Published
2020-06-19
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2, when serving as an OAuth 2.0 Service Provider. There is low entropy for authorization data.
CVSS Score
9.1
EPSS Score
0.011
Published
2020-06-19
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to gain privileges by using a registered OAuth application with personal access tokens.
CVSS Score
8.1
EPSS Score
0.008
Published
2020-06-19
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to gain privileges by accessing unintended API endpoints on a user's behalf.
CVSS Score
9.8
EPSS Score
0.012
Published
2020-06-19
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows a bypass of restrictions on use of slash commands.
CVSS Score
8.8
EPSS Score
0.009
Published
2020-06-19


Contact Us

Shodan ® - All rights reserved