Skip to content

Mattermost Cross-site Scripting vulnerability

Low severity GitHub Reviewed Published Dec 29, 2023 to the GitHub Advisory Database • Updated Aug 7, 2024

Package

gomod github.com/mattermost/mattermost/server/v8 (Go)

Affected versions

< 8.1.7

Patched versions

8.1.7

Description

Mattermost version 8.1.6 and earlier fails to sanitize channel mention data in posts, which allows an attacker to inject markup in the web client.

References

Published by the National Vulnerability Database Dec 29, 2023
Published to the GitHub Advisory Database Dec 29, 2023
Reviewed Jan 3, 2024
Last updated Aug 7, 2024

Severity

Low
3.7
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
High
Privileges required
Low
User interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N

Weaknesses

CVE ID

CVE-2023-7113

GHSA ID

GHSA-h3gq-j7p9-x3p4

Source code

Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.