CVE-2017-18890Improper Input Validation in Mattermost Mattermost-server

Severity
4.3MEDIUMNVD
EPSS
0.3%
top 51.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 19
Latest updateDec 15

Description

An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows an attacker to create a button that, when pressed by a user, launches an API request.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages2 packages

NVDmattermost/mattermost_server4.2.04.2.1+2
Gogithub.com/mattermost_mattermost-server4.2.0-rc14.2.1+5

🔴Vulnerability Details

4
OSV
Mattermost Server allows attackers to create buttons that can launch API requests in github.com/mattermost/mattermost-server2025-12-15
GHSA
Mattermost Server allows attackers to create buttons that can launch API requests2022-05-24
OSV
Mattermost Server allows attackers to create buttons that can launch API requests2022-05-24
CVEList
CVE-2017-18890: An issue was discovered in Mattermost Server before 42020-06-19
CVE-2017-18890 — Improper Input Validation | cvebase