Vulnerabilities
Vulnerable Software
A stack overflow bug in the document extractor in Mattermost Server in versions up to and including 6.3.2 allows an attacker to crash the server via submitting a maliciously crafted Apple Pages document.
CVSS Score
4.3
EPSS Score
0.009
Published
2022-03-10
Mattermost 6.0 and earlier fails to sufficiently validate the email address during registration, which allows attackers to trick users into signing up using attacker-controlled email addresses via crafted invitation token.
CVSS Score
3.7
EPSS Score
0.007
Published
2021-12-17
Mattermost 6.0 and earlier fails to sufficiently validate parameters during post creation, which allows authenticated attackers to cause a client-side crash of the web application via a maliciously crafted post.
CVSS Score
3.5
EPSS Score
0.008
Published
2021-12-17
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows a password reset to proceed while an e-mail address is being changed.
CVSS Score
5.3
EPSS Score
0.008
Published
2020-06-19
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. Users can deactivate themselves, bypassing a policy.
CVSS Score
5.4
EPSS Score
0.008
Published
2020-06-19
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows attackers to obtain sensitive information about whether someone has 2FA enabled.
CVSS Score
5.3
EPSS Score
0.009
Published
2020-06-19
An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. Changes, within the application, to e-mail addresses are mishandled.
CVSS Score
4.3
EPSS Score
0.007
Published
2020-06-19
An issue was discovered in Mattermost Server before 5.8.0. It mishandles brute-force attacks against MFA.
CVSS Score
7.3
EPSS Score
0.008
Published
2020-06-19
An issue was discovered in Mattermost Server before 5.8.0. It does not honor the domain requirement when processing a join request for an open team.
CVSS Score
5.3
EPSS Score
0.008
Published
2020-06-19
An issue was discovered in Mattermost Server before 5.8.0, when Town Square is set to Read-Only. Users can pin or unpin a post.
CVSS Score
4.3
EPSS Score
0.006
Published
2020-06-19


Contact Us

Shodan ® - All rights reserved