PT-2023-29295 · Unknown · Mattermost

0Aqd

·

Publicado

2023-08-25

·

Atualizado

2024-03-06

·

CVE-2023-4478

CVSS v3.1

8.2

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions Mattermost (affected versions not specified)
Description The issue allows an attacker to register users as inactive during signup by manipulating parameters, thus blocking them from later accessing the system without the system admin activating their accounts.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Special Elements Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BIT-MATTERMOST-2023-4478
CVE-2023-4478

Produtos afetados

Mattermost