ZeroHour

CVE-2023-7114

CVSS 3.1
8.8 high
EPSS
<1%p39
Published
()
Modified
Description

Mattermost version 2.10.0 and earlier fails to sanitize deeplink paths, which allows an attacker to perform CSRF attacks against the server.

Vendors
mattermost
Products
mattermost
Weakness
CWE-74, CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.