Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Mattermost | Mattermost App Framework | 0 ~ 7.8.4 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-2793 | 6.5 MEDIUM | Stack exhaustion in PreparePostForClientWithEmbedsAndImages |
| CVE-2023-2792 | 6.5 MEDIUM | Ephemeral messages return private channel contents in permalink previews |
| CVE-2023-2787 | 6.5 MEDIUM | Collapsed Reply Threads APIs leak message contents from private channels |
| CVE-2023-2788 | 6.2 MEDIUM | Deactivated user can retain access using oauth2 api |
| CVE-2023-2785 | 4.3 MEDIUM | Specially crafted search query can cause large log entries in postgres |
| CVE-2023-2831 | 4.3 MEDIUM | Denial of Service while unescaping a Markdown string |
| CVE-2023-2791 | 4.3 MEDIUM | Playbooks lets you edit arbitrary posts |
| CVE-2023-2786 | 4.3 MEDIUM | Channel commands execution doesn't properly verify permissions |
| CVE-2023-2783 | 4.3 MEDIUM | App Framework does not checks for the secret provided in the incoming webhook request |
| CVE-2023-2797 | 3.1 LOW | Path traversal in GitHub plugin's code preview feature |
No comments yet