Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-7113


Mattermost version 8.1.6 and earlier fails to sanitize channel mention data in posts, which allows an attacker to inject markup in the web client.


Published

2023-12-29T13:15:11.930

Last Modified

2024-11-21T08:45:18.417

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 3.7 (LOW)

Weaknesses
  • Type: Secondary
    CWE-79
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application mattermost mattermost_server < 8.1.7 Yes

References