CVE-2017-18884
- EPSS 0.21%
- Veröffentlicht 19.06.2020 19:15:10
- Zuletzt bearbeitet 21.11.2024 03:21:10
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to gain privileges by using a registered OAuth application with personal access tokens.
CVE-2017-18885
- EPSS 0.41%
- Veröffentlicht 19.06.2020 19:15:10
- Zuletzt bearbeitet 21.11.2024 03:21:10
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to gain privileges by accessing unintended API endpoints on a user's behalf.
CVE-2017-18886
- EPSS 0.34%
- Veröffentlicht 19.06.2020 19:15:10
- Zuletzt bearbeitet 21.11.2024 03:21:10
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows a bypass of restrictions on use of slash commands.
CVE-2017-18887
- EPSS 0.24%
- Veröffentlicht 19.06.2020 19:15:10
- Zuletzt bearbeitet 21.11.2024 03:21:10
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It discloses the team creator's e-mail address to members.
CVE-2017-18888
- EPSS 0.42%
- Veröffentlicht 19.06.2020 19:15:10
- Zuletzt bearbeitet 21.11.2024 03:21:11
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows SQL injection during the fetching of multiple posts.
CVE-2017-18889
- EPSS 0.23%
- Veröffentlicht 19.06.2020 19:15:10
- Zuletzt bearbeitet 21.11.2024 03:21:11
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. An attacker could create fictive system-message posts via webhooks and slash commands, in the v3 or v4 REST API.
CVE-2017-18890
- EPSS 0.26%
- Veröffentlicht 19.06.2020 19:15:10
- Zuletzt bearbeitet 21.11.2024 03:21:11
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows an attacker to create a button that, when pressed by a user, launches an API request.
CVE-2017-18891
- EPSS 0.2%
- Veröffentlicht 19.06.2020 19:15:10
- Zuletzt bearbeitet 21.11.2024 03:21:11
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows Phishing because an error page can have a link.
CVE-2017-18892
- EPSS 0.24%
- Veröffentlicht 19.06.2020 19:15:10
- Zuletzt bearbeitet 21.11.2024 03:21:11
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. E-mail templates can have a field in which HTML content is not neutralized.
CVE-2017-18893
- EPSS 0.36%
- Veröffentlicht 19.06.2020 19:15:10
- Zuletzt bearbeitet 21.11.2024 03:21:11
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. Display names allow XSS.