High
CVSS 7.1
Overview
Mattermost version 2.10.0 and earlier fails to sanitize deeplink paths, which allows an attacker to perform CSRF attacks against the server.
Mattermost version 2.10.0 and earlier fails to sanitize deeplink paths, which al...
Mattermost version 2.10.0 and earlier fails to sanitize deeplink paths, which allows an attacker to perform CSRF attacks against the server.
This vulnerability is rated 🟠 HIGH.
Recommended actions: