Mattermost

Mattermost Server

312 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.42%
  • Published 19.06.2020 19:15:10
  • Last modified 21.11.2024 03:21:11

An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows SQL injection during the fetching of multiple posts.

  • EPSS 0.23%
  • Published 19.06.2020 19:15:10
  • Last modified 21.11.2024 03:21:11

An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. An attacker could create fictive system-message posts via webhooks and slash commands, in the v3 or v4 REST API.

  • EPSS 0.26%
  • Published 19.06.2020 19:15:10
  • Last modified 21.11.2024 03:21:11

An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows an attacker to create a button that, when pressed by a user, launches an API request.

  • EPSS 0.2%
  • Published 19.06.2020 19:15:10
  • Last modified 21.11.2024 03:21:11

An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows Phishing because an error page can have a link.

  • EPSS 0.24%
  • Published 19.06.2020 19:15:10
  • Last modified 21.11.2024 03:21:11

An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. E-mail templates can have a field in which HTML content is not neutralized.

  • EPSS 0.36%
  • Published 19.06.2020 19:15:10
  • Last modified 21.11.2024 03:21:11

An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. Display names allow XSS.

  • EPSS 0.21%
  • Published 19.06.2020 19:15:10
  • Last modified 21.11.2024 03:21:12

An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5, when used as an OAuth 2.0 service provider. Sometimes. resource-owner authorization is bypassed, allowing account takeover.

  • EPSS 0.72%
  • Published 19.06.2020 19:15:09
  • Last modified 21.11.2024 03:21:09

An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage for files is used. A System Admin can achieve directory traversal.

  • EPSS 0.15%
  • Published 19.06.2020 18:15:10
  • Last modified 21.11.2024 03:21:08

An issue was discovered in Mattermost Server before 4.4.3 and 4.3.3. Attackers could reconfigure an OAuth app in some cases where Mattermost is an OAuth 2.0 service provider.

  • EPSS 0.38%
  • Published 19.06.2020 18:15:10
  • Last modified 21.11.2024 03:21:08

An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to cause a denial of service (channel invisibility) via a misformatted post.