cbcvebase.
CVE-2023-4478
published 2023-08-25

CVE-2023-4478: Mattermost fails to restrict which parameters' values it takes from the request during signup allowing an attacker to register users as inactive, thus blocking…

PriorityP340high8.2CVSS 3.1
AVNACLPRNUINSUCNILAH
EPSS
0.44%
35.8th percentile
Mattermost fails to restrict which parameters' values it takes from the request during signup allowing an attacker to register users as inactive, thus blocking them from later accessing Mattermost without the system admin activating their accounts.

Affected

5 ranges
VendorProductVersion rangeFixed in
mattermostmattermost<= 7.8.8
mattermostmattermost
mattermostmattermost_server< 7.8.97.8.9
mattermostmattermost_server
mattermostmattermost_server>= 7.9.0 < 7.10.57.10.5
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.