E-Mail containing malicious display-name information could trigger client-side script execution when using specific mobile devices. Attackers could perform malicious API requests or extract information from the users account. Please deploy the provided updates and patch releases. We now use safer methods of handling external content when embedding displayname information to the web interface. No publicly available exploits are known.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: OX
Published: 2024-05-06T06:36:38.440Z
Updated: 2024-08-01T22:59:32.072Z
Reserved: 2024-01-12T07:03:12.862Z
Link: CVE-2024-23186
Vulnrichment
Updated: 2024-08-01T22:59:32.072Z
NVD
Status : Awaiting Analysis
Published: 2024-05-06T07:15:06.450
Modified: 2024-05-07T01:15:06.237
Link: CVE-2024-23186
Redhat
No data.