CVE-2023-5968

Publication date

2023-11-06 15:35:14

Family

Mattermost

State

PUBLISHED

Description

Mattermost fails to properly sanitize the user object when updating the username, resulting in the password hash being included in the response body.