Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-7114
HistoryDec 29, 2023 - 1:15 p.m.

Cross site request forgery (csrf)

2023-12-2913:15:00
PRIOn knowledge base
www.prio-n.com
4
cross site request forgery
mattermost
version 2.10.0
deeplink paths
csrf attacks
server vulnerability

7.2 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

39.4%

Mattermost version 2.10.0 and earlier fails to sanitize deeplink paths, which allows an attacker to perform CSRF attacks against the server.

CPENameOperatorVersion
mattermostlt2.10.1
mattermostlt2.10.1

7.2 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

39.4%

Related for PRION:CVE-2023-7114