First published: Wed Mar 15 2023(Updated: )
A reflected cross-site scripting vulnerability in the OAuth flow completion endpoints in Mattermost allows an attacker to send AJAX requests on behalf of the victim via sharing a crafted link with a malicious state parameter.
Credit: responsibledisclosure@mattermost.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mattermost Mattermost Server | >=5.32.0<7.7.0 |
Update Mattermost to version v7.7 or higher.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-1421 is a reflected cross-site scripting vulnerability in the OAuth flow completion endpoints in Mattermost.
CVE-2023-1421 allows an attacker to send AJAX requests on behalf of the victim via a crafted link with a malicious state parameter.
The vulnerability affects Mattermost Server versions between 5.32.0 and 7.7.0.
CVE-2023-1421 has a severity level of medium with a CVSS score of 6.1.
To fix CVE-2023-1421, update Mattermost Server to a version higher than 7.7.0.