Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
mattermost mattermost boards vulnerabilities and exploits
(subscribe to this query)
5
CVSSv2
CVE-2021-37866
Mattermost Boards plugin v0.10.0 and previous versions fails to invalidate a session on the server-side when a user logged out of Boards, which allows an malicious user to reuse old session token for authorization.
Mattermost Mattermost Boards
4
CVSSv2
CVE-2021-37867
Mattermost Boards plugin v0.10.0 and previous versions fails to protect email addresses of all users via one of the Boards APIs, which allows authenticated and unauthorized users to access this information resulting in sensitive & private information disclosure.
Mattermost Mattermost Boards
NA
CVE-2023-48268
Mattermost fails to limit the amount of data extracted from compressed archives during board import in Mattermost Boards allowing an malicious user to consume excessive resources, possibly leading to Denial of Service, by importing a board using a specially crafted zip (zip bomb)...
Mattermost Mattermost
Mattermost Mattermost 9.1.0
NA
CVE-2023-6202
Mattermost fails to perform proper authorization in the /plugins/focalboard/api/v2/users endpoint allowing an attacker who is a guest user and knows the ID of another user to get their information (e.g. name, surname, nickname) via Mattermost Boards.
Mattermost Mattermost
NA
CVE-2023-45223
Mattermost fails to properly validate the "Show Full Name" option in a few endpoints in Mattermost Boards, allowing a member to get the full name of another user even if the Show Full Name option was disabled.
Mattermost Mattermost
NA
CVE-2023-40703
Mattermost fails to properly limit the characters allowed in different fields of a block in Mattermost Boards allowing a malicious user to consume excessive resources, possibly leading to Denial of Service, by patching the field of a block using a specially crafted string.
Mattermost Mattermost
Mattermost Mattermost 9.1.0
NA
CVE-2023-3585
Mattermost Boards fail to properly validate a board link, allowing an malicious user to crash a channel by posting a specially crafted boards link.
Mattermost Mattermost Server
NA
CVE-2023-3586
Mattermost fails to disable public Boards after the "Enable Publicly-Shared Boards" configuration option is disabled, resulting in previously-shared public Boards to remain accessible.
Mattermost Mattermost Server
NA
CVE-2023-3590
Mattermost fails to delete card attachments in Boards, allowing an malicious user to access deleted attachments.
Mattermost Mattermost Server
NA
CVE-2023-1776
Boards in Mattermost allows an malicious user to upload a malicious SVG image file as an attachment to a card and share it using a direct link to the file.
Mattermost Mattermost Server 7.7.1
Mattermost Mattermost Server
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
path traversal
CVE-2024-33545
CVE-2024-35725
CVE-2024-32704
overflow
file upload
CVE-2024-0230
CVE-2024-32705
CVE-2024-23692
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started