CVE-2023-7114

Publication date

2023-12-29 12:46:22

Family

Mattermost

State

PUBLISHED

Description

Mattermost version 2.10.0 and earlier fails to sanitize deeplink paths, which allows an attacker to perform CSRF attacks against the server.