CVE-2017-18907: XSS
Published Jun 19, 2020
·Updated
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. XSS could occur via a channel header.
Affected Software
2 affected components
Mattermost Mattermost Server<3.9.2
Mattermost Mattermost Server>=3.10.0<3.10.2
Event History
Jun 19, 2020
CVE Published
via MITRE·07:19 PM
Data Sourced
via MITRE·07:19 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-18907?
The severity of CVE-2017-18907 is medium, with a severity value of 6.1.
2
How does CVE-2017-18907 impact Mattermost Server?
CVE-2017-18907 impacts Mattermost Server before version 4.0.0, 3.10.2, and 3.9.2 by allowing XSS attacks via a channel header.
3
How can I fix CVE-2017-18907 in Mattermost Server?
To fix CVE-2017-18907 in Mattermost Server, update to version 4.0.0 or any version higher than 3.10.2 or 3.9.2.
4
Where can I find more information about CVE-2017-18907?
More information about CVE-2017-18907 can be found at the following link: https://mattermost.com/security-updates/
5
What is the Common Weakness Enumeration (CWE) for CVE-2017-18907?
The Common Weakness Enumeration (CWE) for CVE-2017-18907 is CWE-79.