Vulnerabilities > CVE-2021-37862 - Improper Check for Unusual or Exceptional Conditions vulnerability in Mattermost Server

047910
CVSS 5.4 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
LOW
Integrity impact
LOW
Availability impact
NONE
network
low complexity
mattermost
CWE-754

Summary

Mattermost 6.0 and earlier fails to sufficiently validate the email address during registration, which allows attackers to trick users into signing up using attacker-controlled email addresses via crafted invitation token.

Vulnerable Configurations

Part Description Count
Application
Mattermost
585