Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Reflected XSS in OAuth flow completion endpoints
Vulnerability Description
A reflected cross-site scripting vulnerability in the OAuth flow completion endpoints in Mattermost allows an attacker to send AJAX requests on behalf of the victim via sharing a crafted link with a malicious state parameter.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
Mattermost 跨站脚本漏洞
Vulnerability Description
Mattermost是美国Mattermost公司的一个开源协作平台。 Mattermost OAuth存在安全漏洞,该漏洞源于存在反射型跨站脚本漏洞,攻击者利用该漏洞可以通过共享带有恶意状态参数的特制链接代表受害者发送AJAX请求。
CVSS Information
N/A
Vulnerability Type
N/A