CVE-2023-35075
27.11.2023, 10:15
Mattermost fails to use innerText /textContentwhen setting the channel name in the webapp during autocomplete, allowing an attacker to inject HTML to a victim's page by create a channel name that is valid HTML. No XSS is possible though.
Vendor | Product | Version |
---|---|---|
mattermost | mattermost | 𝑥 ≤ 7.8.12 |
mattermost | mattermost | 8.0.0 ≤ 𝑥 ≤ 8.1.3 |
𝑥
= Vulnerable software versions