CVE-2017-18888
- EPSS 0.42%
- Published 19.06.2020 19:15:10
- Last modified 21.11.2024 03:21:11
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows SQL injection during the fetching of multiple posts.
CVE-2017-18889
- EPSS 0.23%
- Published 19.06.2020 19:15:10
- Last modified 21.11.2024 03:21:11
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. An attacker could create fictive system-message posts via webhooks and slash commands, in the v3 or v4 REST API.
CVE-2017-18890
- EPSS 0.26%
- Published 19.06.2020 19:15:10
- Last modified 21.11.2024 03:21:11
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows an attacker to create a button that, when pressed by a user, launches an API request.
CVE-2017-18891
- EPSS 0.2%
- Published 19.06.2020 19:15:10
- Last modified 21.11.2024 03:21:11
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows Phishing because an error page can have a link.
CVE-2017-18892
- EPSS 0.24%
- Published 19.06.2020 19:15:10
- Last modified 21.11.2024 03:21:11
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. E-mail templates can have a field in which HTML content is not neutralized.
CVE-2017-18893
- EPSS 0.36%
- Published 19.06.2020 19:15:10
- Last modified 21.11.2024 03:21:11
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. Display names allow XSS.
CVE-2017-18894
- EPSS 0.21%
- Published 19.06.2020 19:15:10
- Last modified 21.11.2024 03:21:12
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5, when used as an OAuth 2.0 service provider. Sometimes. resource-owner authorization is bypassed, allowing account takeover.
CVE-2017-18874
- EPSS 0.72%
- Published 19.06.2020 19:15:09
- Last modified 21.11.2024 03:21:09
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage for files is used. A System Admin can achieve directory traversal.
CVE-2017-18872
- EPSS 0.15%
- Published 19.06.2020 18:15:10
- Last modified 21.11.2024 03:21:08
An issue was discovered in Mattermost Server before 4.4.3 and 4.3.3. Attackers could reconfigure an OAuth app in some cases where Mattermost is an OAuth 2.0 service provider.
CVE-2017-18873
- EPSS 0.38%
- Published 19.06.2020 18:15:10
- Last modified 21.11.2024 03:21:08
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to cause a denial of service (channel invisibility) via a misformatted post.