CVE-2023-49809

Publication date

2023-12-12 08:20:08

Family

Mattermost

State

PUBLISHED

Description

Mattermost fails to handle a null request body in the /add endpoint, allowing a simple member to send a request with null request body to that endpoint and make it crash. After a few repetitions, the plugin is disabled.