CVE-2017-18913: XSS
Published Jun 19, 2020
·Updated
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. XSS can occur via a link on an error page.
Affected Software
3 affected components
Mattermost Mattermost Server<3.6.7
Mattermost Mattermost Server>=3.7.0<3.7.5
Mattermost Mattermost Server>=3.8.0<3.8.2
Event History
Jun 19, 2020
CVE Published
via MITRE·07:16 PM
Data Sourced
via MITRE·07:16 PM
Description
Frequently Asked Questions
1
What is CVE-2017-18913?
CVE-2017-18913 is an issue discovered in Mattermost Server before version 3.8.2, 3.7.5, and 3.6.7 that allows for XSS attacks via a link on an error page.
2
How severe is CVE-2017-18913?
CVE-2017-18913 has a severity rating of medium, with a CVSS score of 6.1.
3
Which software versions are affected by CVE-2017-18913?
Mattermost Server versions before 3.8.2, 3.7.5, and 3.6.7 are affected by CVE-2017-18913.
4
How can XSS occur via a link on an error page in Mattermost Server?
XSS can occur via a link on an error page in Mattermost Server due to the vulnerability in versions before 3.8.2, 3.7.5, and 3.6.7.
5
What is the Common Vulnerabilities and Exposures (CVE) ID for this vulnerability?
The Common Vulnerabilities and Exposures (CVE) ID for this vulnerability is CVE-2017-18913.