Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Lack of permissions prompting when opening external URLs
Vulnerability Description
Mattermost Desktop App versions <=5.7.0 fail to correctly prompt for permission when opening external URLs which allows a remote attacker to force a victim over the Internet to run arbitrary programs on the victim's system via custom URI schemes.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
Vulnerability Type
保护机制失效
Vulnerability Title
Mattermost Desktop App 安全漏洞
Vulnerability Description
Mattermost Desktop App是美国Mattermost公司的一款消息传递桌面版应用程序。 Mattermost Desktop App 5.7.0及之前版本存在安全漏洞,该漏洞源于在打开外部URL时无法正确提示权限,允许远程攻击者通过自定义URI方案在受害者的系统上运行任意程序。
CVSS Information
N/A
Vulnerability Type
N/A