Description
Mattermost fails to use innerText / textContent when setting the channel name in the webapp during autocomplete, allowing an attacker to inject HTML to a victim's page by create a channel name that is valid HTML. No XSS is possible though.
No analysis available yet.
Remediation
Vendor Solution
Update Mattermost Server to versions 7.8.13, 8.1.4 or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2986 | Mattermost fails to use innerText / textContent when setting the channel name in the webapp during autocomplete, allowing an attacker to inject HTML to a victim's page by create a channel name that is valid HTML. No XSS is possible though. |
Github GHSA |
GHSA-jcgv-3pfq-j4hr | Mattermost Injection vulnerability |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
Tue, 03 Jun 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2025-06-03T14:01:04.187Z
Reserved: 2023-11-20T12:06:31.656Z
Link: CVE-2023-35075
Updated: 2024-08-02T16:23:58.680Z
Status : Modified
Published: 2023-11-27T10:15:07.257
Modified: 2024-11-21T08:07:55.753
Link: CVE-2023-35075
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA