Description
A reflected cross-site scripting vulnerability in the OAuth flow completion endpoints in Mattermost allows an attacker to send AJAX requests on behalf of the victim via sharing a crafted link with a malicious state parameter.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Update Mattermost to version v7.7 or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-23674 | A reflected cross-site scripting vulnerability in the OAuth flow completion endpoints in Mattermost allows an attacker to send AJAX requests on behalf of the victim via sharing a crafted link with a malicious state parameter. |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates/ |
|
History
Fri, 06 Dec 2024 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-12-06T23:06:14.595Z
Reserved: 2023-03-15T22:45:54.197Z
Link: CVE-2023-1421
Updated: 2024-08-02T05:49:11.322Z
Status : Modified
Published: 2023-03-15T23:15:09.467
Modified: 2024-11-21T07:39:09.463
Link: CVE-2023-1421
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD