Description
Mattermost version 8.1.6 and earlier fails to sanitize channel mention data in posts, which allows an attacker to inject markup in the web client.
No analysis available yet.
Remediation
Vendor Solution
Update Mattermost Server to versions 8.1.7, 9.2.0 or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-3217 | Mattermost version 8.1.6 and earlier fails to sanitize channel mention data in posts, which allows an attacker to inject markup in the web client. |
Github GHSA |
GHSA-h3gq-j7p9-x3p4 | Mattermost Cross-site Scripting vulnerability |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
No history.
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-08-02T08:50:08.283Z
Reserved: 2023-12-26T10:19:31.976Z
Link: CVE-2023-7113
No data.
Status : Modified
Published: 2023-12-29T13:15:11.930
Modified: 2026-06-17T06:52:05.683
Link: CVE-2023-7113
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
EUVD
Github GHSA