CVE-2023-35075
EUVD-2023-298627.11.2023, 10:15
Mattermost fails to use innerText / textContent when setting the channel name in the webapp during autocomplete, allowing an attacker to inject HTML to a victim's page by create a channel name that is valid HTML. No XSS is possible though.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| mattermost | mattermost | 𝑥 ≤ 7.8.12 |
| mattermost | mattermost | 8.0.0 ≤ 𝑥 ≤ 8.1.3 |
𝑥
= Vulnerable software versions