CVE-2023-1421
15.03.2023, 23:15
A reflected cross-site scripting vulnerability in the OAuth flow completion endpoints in Mattermost allows an attacker to send AJAX requests on behalf of the victim via sharing a crafted link with a malicious state parameter.
Vendor | Product | Version |
---|---|---|
mattermost | mattermost_server | 5.32.0 ≤ 𝑥 < 7.7.0 |
𝑥
= Vulnerable software versions