Vulnerabilities > Mattermost > Mattermost > 6.3.1
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-03-18 | CVE-2022-1002 | Cross-site Scripting vulnerability in Mattermost Mattermost 6.3.0 and earlier fails to properly sanitize the HTML content in the email invitation sent to guest users, which allows registered users with special permissions to invite guest users to inject unescaped HTML content in the email invitations. | 3.5 |
2022-03-18 | CVE-2022-1003 | Improper Privilege Management vulnerability in Mattermost One of the API in Mattermost version 6.3.0 and earlier fails to properly protect the permissions, which allows the system administrators to combine the two distinct privileges/capabilities in a way that allows them to override certain restricted configurations like EnableUploads. | 4.0 |