CVE-2017-18904: XSS
Published Jun 19, 2020
·Updated
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. It allows XSS via an uploaded file.
Affected Software
2 affected components
Mattermost Mattermost Server<3.9.2
Mattermost Mattermost Server>=3.10.0<3.10.2
Event History
Jun 19, 2020
CVE Published
via MITRE·06:45 PM
Data Sourced
via MITRE·06:45 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-18904?
CVE-2017-18904 is classified as a moderate severity XSS vulnerability affecting Mattermost server versions prior to 4.0.0.
2
How do I fix CVE-2017-18904?
To fix CVE-2017-18904, upgrade Mattermost Server to version 4.0.0 or later, or to 3.10.2 or later if using version 3.
3
What software versions are affected by CVE-2017-18904?
CVE-2017-18904 affects Mattermost Server versions up to 3.9.2 and between 3.10.0 to 3.10.2.
4
What type of vulnerability is CVE-2017-18904?
CVE-2017-18904 is a cross-site scripting (XSS) vulnerability that allows an attacker to exploit uploaded files.
5
Can I still use Mattermost if I have CVE-2017-18904?
Using Mattermost with CVE-2017-18904 presents security risks, so it is recommended to upgrade to a patched version.