Mattermost allows an attacker to request a preview of an existing message when creating a new message via the createPost API call, disclosing the contents of the linked message.
2023-03-31T12:15:06.803
2024-11-21T07:39:53.243
Modified
CVSSv3.1: 6.5 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mattermost | mattermost_server | < 7.1.6 | Yes |
Application | mattermost | mattermost_server | 7.7.1 | Yes |
Application | mattermost | mattermost_server | 7.8.0 | Yes |