Description
Boards in Mattermost allows an attacker to upload a malicious SVG image file as an attachment to a card and share it using a direct link to the file.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Update Mattermost to version v7.8.0, v7.1.6, v7.7.2, or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-0891 | Boards in Mattermost allows an attacker to upload a malicious SVG image file as an attachment to a card and share it using a direct link to the file. |
Github GHSA |
GHSA-63f2-6959-2pxj | Mattermost vulnerable to cross-site scripting (XSS) |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates/ |
|
History
Fri, 06 Dec 2024 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-12-06T23:05:30.076Z
Reserved: 2023-03-31T11:29:24.127Z
Link: CVE-2023-1776
Updated: 2024-08-02T05:57:25.242Z
Status : Modified
Published: 2023-03-31T12:15:06.750
Modified: 2024-11-21T07:39:53.130
Link: CVE-2023-1776
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA