Security Advisory

CVE-2023-47168

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2023-11-27 09:12:52
Last updated 2024-12-02 19:32:41
Assigner Mattermost
State PUBLISHED

Description

Mattermost fails to properly check a redirect URL parameter allowing for an open redirect was possible when the user clicked "Back to Mattermost" after providing a invalid custom url scheme in /oauth/{service}/mobile_login?redirect_to=