Vulnerabilities
Vulnerable Software
Mattermost:  >> Mattermost Mobile  Security Vulnerabilities
Mattermost Mobile Apps versions <=2.25.0  fail to terminate sessions during logout under certain conditions (e.g. poor connectivity), allowing unauthorized users on shared devices to access sensitive notification content via continued mobile notifications
CVSS Score
2.0
EPSS Score
0.0
Published
2025-04-14
Mattermost Mobile Apps versions <=2.25.0 fail to properly validate GIF images prior to rendering which allows a malicious user to cause the Android application to crash via message containing a maliciously crafted GIF.
CVSS Score
6.5
EPSS Score
0.001
Published
2025-03-24
Mattermost Mobile versions <=2.22.0 fail to properly handle posts with attachments containing fields that cannot be cast to a String, which allows an attacker to cause the mobile to crash via creating and sending such a post to a channel.
CVSS Score
6.5
EPSS Score
0.002
Published
2025-01-16
Mattermost Mobile versions <= 2.22.0 fail to properly validate the style of proto supplied to an action's style in post.props.attachments, which allows an attacker to crash the mobile via crafted malicious input.
CVSS Score
6.5
EPSS Score
0.001
Published
2025-01-16
Mattermost Mobile Apps versions <=2.22.0 fail to properly handle specially crafted attachment names, which allows an attacker to crash the mobile app for any user who opened a channel containing the specially crafted attachment
CVSS Score
4.3
EPSS Score
0.003
Published
2025-01-16
Mattermost Mobile Apps versions <=2.22.0 fail to properly validate post props which allows a malicious authenticated user to cause a crash via a malicious post.
CVSS Score
6.5
EPSS Score
0.002
Published
2025-01-15
Mattermost Mobile Apps versions <=2.22.0 fail to properly validate post props which allows a malicious authenticated user to cause a crash via a malicious post.
CVSS Score
6.5
EPSS Score
0.002
Published
2025-01-15
Mattermost Android Mobile Apps versions <=2.21.0 fail to properly configure file providers which allows an attacker with local access to access files via file provider.
CVSS Score
5.7
EPSS Score
0.0
Published
2024-12-16
Mattermost Mobile Apps versions <=2.18.0 fail to disable autocomplete during login while typing the password and visible password is selected, which allows the password to get saved in the dictionary when the user has Swiftkey as the default keyboard, the masking is off and the password contains a special character..
CVSS Score
4.5
EPSS Score
0.002
Published
2024-09-16
Mattermost Mobile Apps versions <=2.16.0 fail to protect against abuse of a globally shared MathJax state which allows an attacker to change the contents of a LateX post, by creating another post with specific macro definitions.
CVSS Score
2.6
EPSS Score
0.004
Published
2024-07-15


Contact Us

Shodan ® - All rights reserved