Mattermost App Framework vulnerabilities
2 known vulnerabilities affecting mattermost/mattermost_app_framework.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2023-2783MEDIUMCVSS 4.3≤ 7.8.4v7.10.02023-06-16
CVE-2023-2783 [MEDIUM] CWE-862 CVE-2023-2783: Mattermost Apps Framework fails to verify that a secret provided in the incoming webhook request all
Mattermost Apps Framework fails to verify that a secret provided in the incoming webhook request allowing an attacker to modify the contents of the post sent by the Apps.
cvelistv5nvd
CVE-2023-2784MEDIUMCVSS 6.5≤ 7.8.4v7.10.02023-06-16
CVE-2023-2784 [MEDIUM] CWE-862 CVE-2023-2784: Mattermost fails to verify if the requestor is a sysadmin or not, before allowing `install` requests
Mattermost fails to verify if the requestor is a sysadmin or not, before allowing `install` requests to the Apps allowing a regular user send install requests to the Apps.
cvelistv5nvd