|
270851
|
6.1 |
MEDIUM
Network
|
mattermost
|
mattermost_server
|
An issue was discovered in Mattermost Server before 3.1.0. It allows XSS because the noreferrer and noopener protection mechanisms were not in place.
|
CWE-79
Cross-site Scripting
|
CVE-2016-11071
|
2024-11-21 11:45 |
2020-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270852
|
5.4 |
MEDIUM
Network
|
mattermost
|
mattermost_server
|
An issue was discovered in Mattermost Server before 3.1.0. It allows XSS via theme color-code values.
|
CWE-79
Cross-site Scripting
|
CVE-2016-11070
|
2024-11-21 11:45 |
2020-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270853
|
7.5 |
HIGH
Network
|
mattermost
|
mattermost_server
|
An issue was discovered in Mattermost Server before 3.2.0. It mishandles brute-force attempts at password change.
|
CWE-521
Weak Password Requirements
|
CVE-2016-11069
|
2024-11-21 11:45 |
2020-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270854
|
5.3 |
MEDIUM
Network
|
mattermost
|
mattermost_server
|
An issue was discovered in Mattermost Server before 3.2.0. Attackers could read LDAP fields via injection.
|
CWE-74
Injection
|
CVE-2016-11068
|
2024-11-21 11:45 |
2020-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270855
|
5.3 |
MEDIUM
Network
|
mattermost
|
mattermost_server
|
An issue was discovered in Mattermost Server before 3.2.0. It allowed crafted posts that could cause a web browser to hang.
|
CWE-20
Improper Input Validation
|
CVE-2016-11067
|
2024-11-21 11:45 |
2020-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270856
|
7.5 |
HIGH
Network
|
mattermost
|
mattermost_server
|
An issue was discovered in Mattermost Server before 3.2.0. The initial_load API disclosed unnecessary personal information.
|
CWE-200
Information Exposure
|
CVE-2016-11066
|
2024-11-21 11:45 |
2020-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270857
|
4.3 |
MEDIUM
Network
|
mattermost
|
mattermost_server
|
An issue was discovered in Mattermost Server before 3.3.0. An attacker could use the WebSocket feature to send pop-up messages to users or change a post's appearance.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2016-11065
|
2024-11-21 11:45 |
2020-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270858
|
9.8 |
CRITICAL
Network
|
mattermost
|
mattermost_desktop
|
An issue was discovered in Mattermost Desktop App before 3.4.0. Strings could be executed as code via injection.
|
CWE-94
Code Injection
|
CVE-2016-11064
|
2024-11-21 11:45 |
2020-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270859
|
6.1 |
MEDIUM
Network
|
mattermost
|
mattermost_server
|
An issue was discovered in Mattermost Server before 3.5.1. XSS can occur via file preview.
|
CWE-79
Cross-site Scripting
|
CVE-2016-11063
|
2024-11-21 11:45 |
2020-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270860
|
5.3 |
MEDIUM
Network
|
mattermost
|
mattermost_server
|
An issue was discovered in Mattermost Server before 3.5.1. E-mail address verification can be bypassed.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2016-11062
|
2024-11-21 11:45 |
2020-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|