Description
Mattermost version 8.1.6 and earlier fails to sanitize channel mention data in posts, which allows an attacker to inject markup in the web client.
No analysis available yet.
Remediation
Vendor Solution
Update Mattermost Server to versions 8.1.7, 9.2.0 or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-3217 | Mattermost version 8.1.6 and earlier fails to sanitize channel mention data in posts, which allows an attacker to inject markup in the web client. |
Github GHSA |
GHSA-h3gq-j7p9-x3p4 | Mattermost Cross-site Scripting vulnerability |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
No history.
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-08-02T08:50:08.283Z
Reserved: 2023-12-26T10:19:31.976Z
Link: CVE-2023-7113
No data.
Status : Modified
Published: 2023-12-29T13:15:11.930
Modified: 2024-11-21T08:45:18.417
Link: CVE-2023-7113
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA