CVE-2021-37863

LOW

Mattermost < 6.0 - Authenticated Denial of Service via Malicious Post Creation

Title source: llm
STIX 2.1

Description

Mattermost 6.0 and earlier fails to sufficiently validate parameters during post creation, which allows authenticated attackers to cause a client-side crash of the web application via a maliciously crafted post.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_misc
https://mattermost.com/security-updates/
Permissions Required x_refsource_misc
https://hackerone.com/reports/1253732

Scores

CVSS v3 3.5
EPSS 0.0057
EPSS Percentile 68.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L

Details

CWE
CWE-20
Status published
Products (1)
mattermost/mattermost_server < 6.0
Published Dec 17, 2021
Tracked Since Feb 18, 2026