Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:47220
HistoryMay 28, 2024 - 10:10 a.m.

Cross-site Request Forgery (CSRF)

2024-05-2810:10:46
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
5
mattermost
csrf
vulnerability
unauthorized
command execution
deceptive post action

5.7 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N

7 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.0%

Mattermost is vulnerable to Cross-site Request Forgery (CSRF). The vulnerability is due to a failure to validate post actions properly, allowing an attacker to run a playbook checklist task command as another user by creating and sharing a deceptive post action that unexpectedly runs a slash command in an arbitrary channel.

5.7 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N

7 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.0%

Related for VERACODE:47220