CVE-2021-37862
17.12.2021, 17:15
Mattermost 6.0 and earlier fails to sufficiently validate the email address during registration, which allows attackers to trick users into signing up using attacker-controlled email addresses via crafted invitation token.Enginsight
Vendor | Product | Version |
---|---|---|
mattermost | mattermost_server | 𝑥 ≤ 6.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration