Vulnerabilities > CVE-2024-32945 - Missing Initialization of Resource vulnerability in Mattermost Mobile 1.26.0/1.29.0/1.30.0

047910
CVSS 5.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
LOW
Availability impact
NONE
network
low complexity
mattermost
CWE-909

Summary

Mattermost Mobile Apps versions <=2.16.0 fail to protect against abuse of a globally shared MathJax state which allows an attacker to change the contents of a LateX post, by creating another post with specific macro definitions.

Common Weakness Enumeration (CWE)