|
265741
|
6.5 |
MEDIUM
Network
|
mattermost
|
mattermost_server
|
An issue was discovered in Mattermost Server before 3.0.2. The purposes of a session ID and a Session Token were mishandled.
|
CWE-287
Improper Authentication
|
CVE-2016-11072
|
2024-11-21 11:45 |
2020-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265742
|
6.1 |
MEDIUM
Network
|
mattermost
|
mattermost_server
|
An issue was discovered in Mattermost Server before 3.1.0. It allows XSS because the noreferrer and noopener protection mechanisms were not in place.
|
CWE-79
Cross-site Scripting
|
CVE-2016-11071
|
2024-11-21 11:45 |
2020-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265743
|
5.4 |
MEDIUM
Network
|
mattermost
|
mattermost_server
|
An issue was discovered in Mattermost Server before 3.1.0. It allows XSS via theme color-code values.
|
CWE-79
Cross-site Scripting
|
CVE-2016-11070
|
2024-11-21 11:45 |
2020-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265744
|
7.5 |
HIGH
Network
|
mattermost
|
mattermost_server
|
An issue was discovered in Mattermost Server before 3.2.0. It mishandles brute-force attempts at password change.
|
CWE-521
Weak Password Requirements
|
CVE-2016-11069
|
2024-11-21 11:45 |
2020-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265745
|
5.3 |
MEDIUM
Network
|
mattermost
|
mattermost_server
|
An issue was discovered in Mattermost Server before 3.2.0. Attackers could read LDAP fields via injection.
|
CWE-74
Injection
|
CVE-2016-11068
|
2024-11-21 11:45 |
2020-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265746
|
5.3 |
MEDIUM
Network
|
mattermost
|
mattermost_server
|
An issue was discovered in Mattermost Server before 3.2.0. It allowed crafted posts that could cause a web browser to hang.
|
CWE-20
Improper Input Validation
|
CVE-2016-11067
|
2024-11-21 11:45 |
2020-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265747
|
7.5 |
HIGH
Network
|
mattermost
|
mattermost_server
|
An issue was discovered in Mattermost Server before 3.2.0. The initial_load API disclosed unnecessary personal information.
|
CWE-200
Information Exposure
|
CVE-2016-11066
|
2024-11-21 11:45 |
2020-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265748
|
4.3 |
MEDIUM
Network
|
mattermost
|
mattermost_server
|
An issue was discovered in Mattermost Server before 3.3.0. An attacker could use the WebSocket feature to send pop-up messages to users or change a post's appearance.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2016-11065
|
2024-11-21 11:45 |
2020-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265749
|
9.8 |
CRITICAL
Network
|
mattermost
|
mattermost_desktop
|
An issue was discovered in Mattermost Desktop App before 3.4.0. Strings could be executed as code via injection.
|
CWE-94
Code Injection
|
CVE-2016-11064
|
2024-11-21 11:45 |
2020-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265750
|
6.1 |
MEDIUM
Network
|
mattermost
|
mattermost_server
|
An issue was discovered in Mattermost Server before 3.5.1. XSS can occur via file preview.
|
CWE-79
Cross-site Scripting
|
CVE-2016-11063
|
2024-11-21 11:45 |
2020-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|