CVE-2023-4478
published 2023-08-25CVE-2023-4478: Mattermost fails to restrict which parameters' values it takes from the request during signup allowing an attacker to register users as inactive, thus blocking…
PriorityP340high8.2CVSS 3.1
AVNACLPRNUINSUCNILAH
EPSS
0.44%
35.8th percentile
Mattermost fails to restrict which parameters' values it takes from the request during signup allowing an attacker to register users as inactive, thus blocking them from later accessing Mattermost without the system admin activating their accounts.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mattermost | mattermost | <= 7.8.8 | — |
| mattermost | mattermost | — | — |
| mattermost | mattermost_server | < 7.8.9 | 7.8.9 |
| mattermost | mattermost_server | — | — |
| mattermost | mattermost_server | >= 7.9.0 < 7.10.5 | 7.10.5 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-08-25
Published