4.9
CVSSv3

CVE-2023-5968

Published: 06/11/2023 Updated: 14/11/2023
CVSS v3 Base Score: 4.9 | Impact Score: 3.6 | Exploitability Score: 1.2
VMScore: 0

Vulnerability Summary

Mattermost fails to properly sanitize the user object when updating the username, resulting in the password hash being included in the response body. 

Vulnerable Product Search on Vulmon Subscribe to Product

mattermost mattermost

mattermost mattermost 9.0.0