cbcvebase.
CVE-2016-11071
published 2020-06-19

CVE-2016-11071: An issue was discovered in Mattermost Server before 3.1.0. It allows XSS because the noreferrer and noopener protection mechanisms were not in place.

medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
An issue was discovered in Mattermost Server before 3.1.0. It allows XSS because the noreferrer and noopener protection mechanisms were not in place.

Affected

3 ranges
VendorProductVersion rangeFixed in
github.commattermost_mattermost-server>= 0 < 3.1.0+incompatible3.1.0+incompatible
github.commattermost_mattermost-server>= 0 < 3.1.03.1.0
mattermostmattermost_server< 3.1.03.1.0