Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
mattermost mattermost vulnerabilities and exploits
(subscribe to this query)
356
VMScore
CVE-2017-18876
An issue exists in Mattermost Server prior to 4.3.0, 4.2.1, and 4.1.2 when local storage for files is used. A System Admin can test for the existence of an arbitrary file.
Mattermost Mattermost Server
Mattermost Mattermost Server 4.3.0
356
VMScore
CVE-2017-18878
An issue exists in Mattermost Server prior to 4.3.0, 4.2.1, and 4.1.2. Knowledge of a session ID allows revoking another user's session.
Mattermost Mattermost Server
Mattermost Mattermost Server 4.3.0
383
VMScore
CVE-2017-18880
An issue exists in Mattermost Server prior to 4.3.0, 4.2.1, and 4.1.2. XSS could occur via the title_link field of a Slack attachment.
Mattermost Mattermost Server
Mattermost Mattermost Server 4.3.0
383
VMScore
CVE-2017-18881
An issue exists in Mattermost Server prior to 4.3.0, 4.2.1, and 4.1.2. XSS could occur via a goto_location response to a slash command.
Mattermost Mattermost Server
Mattermost Mattermost Server 4.3.0
570
VMScore
CVE-2017-18883
An issue exists in Mattermost Server prior to 4.3.0, 4.2.1, and 4.1.2, when serving as an OAuth 2.0 Service Provider. There is low entropy for authorization data.
Mattermost Mattermost Server
Mattermost Mattermost Server 4.3.0
668
VMScore
CVE-2017-18885
An issue exists in Mattermost Server prior to 4.3.0, 4.2.1, and 4.1.2. It allows malicious users to gain privileges by accessing unintended API endpoints on a user's behalf.
Mattermost Mattermost Server
Mattermost Mattermost Server 4.3.0
445
VMScore
CVE-2017-18887
An issue exists in Mattermost Server prior to 4.3.0, 4.2.1, and 4.1.2. It discloses the team creator's e-mail address to members.
Mattermost Mattermost Server
Mattermost Mattermost Server 4.3.0
383
VMScore
CVE-2017-18890
An issue exists in Mattermost Server prior to 4.3.0, 4.2.1, and 4.1.2. It allows an malicious user to create a button that, when pressed by a user, launches an API request.
Mattermost Mattermost Server
Mattermost Mattermost Server 4.3.0
383
VMScore
CVE-2017-18892
An issue exists in Mattermost Server prior to 4.2.0, 4.1.1, and 4.0.5. E-mail templates can have a field in which HTML content is not neutralized.
Mattermost Mattermost Server
Mattermost Mattermost Server 4.2.0
490
VMScore
CVE-2017-18894
An issue exists in Mattermost Server prior to 4.2.0, 4.1.1, and 4.0.5, when used as an OAuth 2.0 service provider. Sometimes. resource-owner authorization is bypassed, allowing account takeover.
Mattermost Mattermost Server
Mattermost Mattermost Server 4.2.0
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-7073
CVE-2024-5496
CVE-2024-5495
XPath injection
bypass
CVE-2024-30043
CVE-2024-24919
denial of service
CVE-2024-35468
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
10
NEXT »