Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
mattermost mattermost vulnerabilities and exploits
(subscribe to this query)
4.9
CVSSv3
CVE-2017-18875
An issue exists in Mattermost Server prior to 4.3.0, 4.2.1, and 4.1.2 when local storage for files is used. A System Admin can create arbitrary files.
Mattermost Mattermost Server
Mattermost Mattermost Server 4.3.0
6.1
CVSSv3
CVE-2017-18877
An issue exists in Mattermost Server prior to 4.3.0, 4.2.1, and 4.1.2. XSS attacks could occur against an OAuth 2.0 allow/deny page.
Mattermost Mattermost Server
Mattermost Mattermost Server 4.3.0
4.3
CVSSv3
CVE-2017-18878
An issue exists in Mattermost Server prior to 4.3.0, 4.2.1, and 4.1.2. Knowledge of a session ID allows revoking another user's session.
Mattermost Mattermost Server
Mattermost Mattermost Server 4.3.0
6.1
CVSSv3
CVE-2017-18880
An issue exists in Mattermost Server prior to 4.3.0, 4.2.1, and 4.1.2. XSS could occur via the title_link field of a Slack attachment.
Mattermost Mattermost Server
Mattermost Mattermost Server 4.3.0
6.1
CVSSv3
CVE-2017-18882
An issue exists in Mattermost Server prior to 4.3.0, 4.2.1, and 4.1.2. XSS can occur via OpenGraph data.
Mattermost Mattermost Server
Mattermost Mattermost Server 4.3.0
9.1
CVSSv3
CVE-2017-18883
An issue exists in Mattermost Server prior to 4.3.0, 4.2.1, and 4.1.2, when serving as an OAuth 2.0 Service Provider. There is low entropy for authorization data.
Mattermost Mattermost Server
Mattermost Mattermost Server 4.3.0
9.8
CVSSv3
CVE-2017-18885
An issue exists in Mattermost Server prior to 4.3.0, 4.2.1, and 4.1.2. It allows malicious users to gain privileges by accessing unintended API endpoints on a user's behalf.
Mattermost Mattermost Server
Mattermost Mattermost Server 4.3.0
8.8
CVSSv3
CVE-2017-18886
An issue exists in Mattermost Server prior to 4.3.0, 4.2.1, and 4.1.2. It allows a bypass of restrictions on use of slash commands.
Mattermost Mattermost Server
Mattermost Mattermost Server 4.3.0
5.3
CVSSv3
CVE-2017-18887
An issue exists in Mattermost Server prior to 4.3.0, 4.2.1, and 4.1.2. It discloses the team creator's e-mail address to members.
Mattermost Mattermost Server
Mattermost Mattermost Server 4.3.0
9.8
CVSSv3
CVE-2017-18888
An issue exists in Mattermost Server prior to 4.3.0, 4.2.1, and 4.1.2. It allows SQL injection during the fetching of multiple posts.
Mattermost Mattermost Server
Mattermost Mattermost Server 4.3.0
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2022-38028
CVE-2024-32406
CVE-2024-25624
IMAP
CVE-2024-2310
CVE-2024-0874
CVE-2024-20359
XXE
remote code execution
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
NEXT »