CVE-2021-37862

LOW

Mattermost < 6.0 - Email Address Spoofing via Crafted Invitation Token

Title source: llm
STIX 2.1

Description

Mattermost 6.0 and earlier fails to sufficiently validate the email address during registration, which allows attackers to trick users into signing up using attacker-controlled email addresses via crafted invitation token.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_misc
https://mattermost.com/security-updates/
Permissions Required x_refsource_misc
https://hackerone.com/reports/1357013

Scores

CVSS v3 3.7
EPSS 0.0017
EPSS Percentile 37.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N

Details

CWE
CWE-754
Status published
Products (1)
mattermost/mattermost_server < 6.0
Published Dec 17, 2021
Tracked Since Feb 18, 2026