|
265961
|
6.1 |
MEDIUM
Network
|
mattermost
|
mattermost_server
|
An issue was discovered in Mattermost Server before 3.0.0. It allows XSS via a Legal or Support setting.
|
CWE-79
Cross-site Scripting
|
CVE-2016-11073
|
2024-11-21 11:45 |
2020-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265962
|
6.5 |
MEDIUM
Network
|
mattermost
|
mattermost_server
|
An issue was discovered in Mattermost Server before 3.0.2. The purposes of a session ID and a Session Token were mishandled.
|
CWE-287
Improper Authentication
|
CVE-2016-11072
|
2024-11-21 11:45 |
2020-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265963
|
6.1 |
MEDIUM
Network
|
mattermost
|
mattermost_server
|
An issue was discovered in Mattermost Server before 3.1.0. It allows XSS because the noreferrer and noopener protection mechanisms were not in place.
|
CWE-79
Cross-site Scripting
|
CVE-2016-11071
|
2024-11-21 11:45 |
2020-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265964
|
5.4 |
MEDIUM
Network
|
mattermost
|
mattermost_server
|
An issue was discovered in Mattermost Server before 3.1.0. It allows XSS via theme color-code values.
|
CWE-79
Cross-site Scripting
|
CVE-2016-11070
|
2024-11-21 11:45 |
2020-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265965
|
7.5 |
HIGH
Network
|
mattermost
|
mattermost_server
|
An issue was discovered in Mattermost Server before 3.2.0. It mishandles brute-force attempts at password change.
|
CWE-521
Weak Password Requirements
|
CVE-2016-11069
|
2024-11-21 11:45 |
2020-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265966
|
5.3 |
MEDIUM
Network
|
mattermost
|
mattermost_server
|
An issue was discovered in Mattermost Server before 3.2.0. Attackers could read LDAP fields via injection.
|
CWE-74
Injection
|
CVE-2016-11068
|
2024-11-21 11:45 |
2020-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265967
|
5.3 |
MEDIUM
Network
|
mattermost
|
mattermost_server
|
An issue was discovered in Mattermost Server before 3.2.0. It allowed crafted posts that could cause a web browser to hang.
|
CWE-20
Improper Input Validation
|
CVE-2016-11067
|
2024-11-21 11:45 |
2020-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265968
|
7.5 |
HIGH
Network
|
mattermost
|
mattermost_server
|
An issue was discovered in Mattermost Server before 3.2.0. The initial_load API disclosed unnecessary personal information.
|
CWE-200
Information Exposure
|
CVE-2016-11066
|
2024-11-21 11:45 |
2020-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265969
|
4.3 |
MEDIUM
Network
|
mattermost
|
mattermost_server
|
An issue was discovered in Mattermost Server before 3.3.0. An attacker could use the WebSocket feature to send pop-up messages to users or change a post's appearance.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2016-11065
|
2024-11-21 11:45 |
2020-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265970
|
9.8 |
CRITICAL
Network
|
mattermost
|
mattermost_desktop
|
An issue was discovered in Mattermost Desktop App before 3.4.0. Strings could be executed as code via injection.
|
CWE-94
Code Injection
|
CVE-2016-11064
|
2024-11-21 11:45 |
2020-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|