Description
Mattermost 6.0 and earlier fails to sufficiently validate the email address during registration, which allows attackers to trick users into signing up using attacker-controlled email addresses via crafted invitation token.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-24340 | Mattermost 6.0 and earlier fails to sufficiently validate the email address during registration, which allows attackers to trick users into signing up using attacker-controlled email addresses via crafted invitation token. |
References
History
No history.
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-08-04T01:30:09.135Z
Reserved: 2021-08-02T00:00:00.000Z
Link: CVE-2021-37862
No data.
Status : Modified
Published: 2021-12-17T17:15:12.920
Modified: 2024-11-21T06:15:59.733
Link: CVE-2021-37862
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD