Mattermost fails to check if hardened mode is enabled when overriding the username and/or the icon when posting a post. If settings allowed integrations to override the username and profile picture when posting, a member could also override the username and icon when making a post even if the Hardened Mode setting was enabled
2023-11-27T09:15:32.587
2024-11-21T08:30:56.033
Modified
CVSSv3.1: 4.3 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mattermost | mattermost | ≤ 7.8.12 | Yes |
Application | mattermost | mattermost | ≤ 8.1.3 | Yes |