Vulnerabilities > Mattermost > Mattermost > 6.2.1
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-03-18 | CVE-2022-1002 | Cross-site Scripting vulnerability in Mattermost Mattermost 6.3.0 and earlier fails to properly sanitize the HTML content in the email invitation sent to guest users, which allows registered users with special permissions to invite guest users to inject unescaped HTML content in the email invitations. | 3.5 |
2022-03-18 | CVE-2022-1003 | Improper Privilege Management vulnerability in Mattermost One of the API in Mattermost version 6.3.0 and earlier fails to properly protect the permissions, which allows the system administrators to combine the two distinct privileges/capabilities in a way that allows them to override certain restricted configurations like EnableUploads. | 4.0 |
2022-02-21 | CVE-2022-0708 | Information Exposure vulnerability in Mattermost Mattermost 6.3.0 and earlier fails to protect email addresses of the creator of the team via one of the APIs, which allows authenticated team members to access this information resulting in sensitive & private information disclosure. | 4.0 |