PT-2023-25131 · Mattermost · Mattermost

Harrison Healey

·

Publicado

2023-11-27

·

Atualizado

2023-11-30

·

CVE-2023-35075

CVSS v3.1

3.1

Baixa

VetorAV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Mattermost (affected versions not specified)
Description The issue arises from Mattermost's failure to use innerText or textContent when setting the channel name in the webapp during autocomplete. This allows an attacker to inject HTML into a victim's page by creating a channel name that is valid HTML. However, it is noted that no Cross-Site Scripting (XSS) is possible.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Special Elements Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-35075
GHSA-JCGV-3PFQ-J4HR

Produtos afetados

Mattermost