Mattermost Mobile Apps是美国Mattermost公司的一款消息传递移动应用程序。 Mattermost Mobile Apps 2.0.37及之前版本、11.0.4及之前版本、11.1.3及之前版本、11.3.2及之前版本和10.11.11.0及之前版本存在跨站请求伪造漏洞,该漏洞源于未正确验证SSO身份验证回调来源,可能导致攻击者窃取用户凭据。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Mattermost | Mattermost | ≤ 2.0.37 |
affected |
≤ 11.0.4 |
affected | ||
≤ 11.1.3 |
affected | ||
≤ 11.3.2 |
affected | ||
≤ 10.11.11 |
affected | ||
2.38.0 |
unaffected | ||
11.5.0 |
unaffected | ||
2.37.1.0 |
unaffected | ||
| … +4 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Mattermost | Mattermost | 0 ~ 2.0.37 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-4858 | 8.0 HIGH | Path traversal in integration action URL leading to arbitrary API execution via system adm |
| CVE-2026-4055 | 4.3 MEDIUM | Insufficient permission validation on cross-team playbook run creation |
No comments yet