CVE-2023-7113

LOW

Mattermost < 8.1.7 - Stored Cross-Site Scripting via Channel Mention Data

Title source: llm
STIX 2.1

Description

Mattermost version 8.1.6 and earlier fails to sanitize channel mention data in posts, which allows an attacker to inject markup in the web client.

References (1)

Core 1
Core References

Scores

CVSS v3 3.7
EPSS 0.0073
EPSS Percentile 72.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (2)
mattermost/mattermost 0 - 8.1.7Go
mattermost/mattermost_server < 8.1.7
Published Dec 29, 2023
Tracked Since Feb 18, 2026