Total vulnerabilities in the database
When creating a playbook run via the /dialog API, Mattermost fails to validate all parameters, allowing an authenticated attacker to edit an arbitrary channel post.
Software | From | Fixed in |
---|---|---|
mattermost / mattermost | 7.7.0 | 7.7.3.x |
mattermost / mattermost | 7.8.0 | 7.8.2.x |
mattermost / mattermost | 7.9.0 | 7.9.1.x |
mattermost / mattermost | 7.10.0 | 7.10.0.x |