Mattermost 桌面应用版本 <=6.2 及 6.2.2.0 在检查目标 URL 是否属于当前连接服务器内部时,未能正确验证 URL 协议(scheme),这允许处于网络位置的攻击者通过一个使用降级 URL 协议的链接,在不安全的连接上加载插件弹出窗口。Mattermost 通告编号:MMSA-2026-007
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Mattermost | Mattermost | ≤ 6.2.2 |
affected |
6.3.0 |
unaffected | ||
6.2.3.0 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Mattermost | Mattermost | 0 ~ 6.2.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet