Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Mattermost | Mattermost | 0 ~ 7.10.2 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-3615 | 8.1 HIGH | Lack of server certificate validation in websockets connection |
| CVE-2023-3581 | 6.2 MEDIUM | WebSockets accept connections from HTTPS origin |
| CVE-2023-3591 | 4.8 MEDIUM | Lack of previous password reset tokens on new token creation |
| CVE-2023-3582 | 4.3 MEDIUM | Lack of channel membership check when linking a board to a channel |
| CVE-2023-3585 | 4.3 MEDIUM | channel DoS by sharing a boards link |
| CVE-2023-3614 | 4.3 MEDIUM | Denial of Service via specially crafted gif image |
| CVE-2023-3593 | 4.3 MEDIUM | Server crash via a specially crafted markdown input |
| CVE-2023-3586 | 4.2 MEDIUM | Disabling publicly-shared boards does not disable existing publicly available board links |
| CVE-2023-3577 | 3.5 LOW | Limited blind SSRF to localhost/intranet in interactive dialog implementation |
| CVE-2023-3613 | 3.5 LOW | Guest accounts invited and added to channels by Welcomebot plugin |
| CVE-2023-3584 | 3.1 LOW | Member can create team with team override scheme |
| CVE-2023-3587 | 2.7 LOW | Inconsistent state in UI after boards permission change by system admin |
No comments yet