Cross-site scripting in Mattermost Server - CVE-2017-18893

 

Cross-site scripting in Mattermost Server - CVE-2017-18893

Published: June 19, 2020 / Updated: July 17, 2020


Vulnerability identifier: #VU30204
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2017-18893
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. Display names allow XSS.


Affected software

Mattermost Server

How to mitigate CVE-2017-18893

Install update from vendor's website.

Mattermost Server - update to 4.1.1

External References

Related Security Bulletins