Mattermost Mobile Apps versions <=2.16.0 fail to protect against abuse of a globally shared MathJax state which allows an attacker to change the contents of a LateX post, by creating another post with specific macro definitions.
2024-07-15T09:15:02.260
2024-11-21T09:16:05.340
Modified
CVSSv3.1: 2.6 (LOW)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mattermost | mattermost_mobile | < 2.17.0 | Yes |