PT-2023-25131 · Mattermost · Mattermost

Harrison Healey

·

Published

2023-11-27

·

Updated

2023-11-30

·

CVE-2023-35075

CVSS v3.1

3.1

Low

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Mattermost (affected versions not specified)
Description The issue arises from Mattermost's failure to use innerText or textContent when setting the channel name in the webapp during autocomplete. This allows an attacker to inject HTML into a victim's page by creating a channel name that is valid HTML. However, it is noted that no Cross-Site Scripting (XSS) is possible.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2023-35075
GHSA-JCGV-3PFQ-J4HR

Affected Products

Mattermost