Mattermost 6.0 and earlier fails to sufficiently validate parameters during post creation, which allows authenticated attackers to cause a client-side crash of the web application via a maliciously crafted post.
References
Link Resource
https://hackerone.com/reports/1253732 Permissions Required
https://mattermost.com/security-updates/ Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: Mattermost

Published: 2021-12-17T16:10:30

Updated: 2021-12-17T16:10:30

Reserved: 2021-08-02T00:00:00


Link: CVE-2021-37863

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-12-17T17:15:12.987

Modified: 2021-12-21T17:29:50.107


Link: CVE-2021-37863

JSON object: View

cve-icon Redhat Information

No data.

CWE