CVE-2023-1421

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
15/03/2023
Last modified:
21/03/2023

Description

A reflected cross-site scripting vulnerability in the OAuth flow completion endpoints in Mattermost allows an attacker to send AJAX requests on behalf of the victim via sharing a crafted link with a malicious state parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* 5.32.0 (including) 7.7.0 (excluding)


References to Advisories, Solutions, and Tools