CVE-2021-37860 - CERT CVE
ID CVE-2021-37860
Sažetak Mattermost 5.38 and earlier fails to sufficiently sanitize clipboard contents, which allows a user-assisted attacker to inject arbitrary web script in product deployments that explicitly disable the default CSP.
Reference
CVSS
Base: 2.6
Impact: 2.9
Exploitability:4.9
Pristup
VektorSloženostAutentikacija
NETWORK HIGH NONE
Impact
PovjerljivostCjelovitostDostupnost
NONE PARTIAL NONE
CVSS vektor AV:N/AC:H/Au:N/C:N/I:P/A:N
Zadnje važnije ažuriranje 05-10-2021 - 17:30
Objavljeno 22-09-2021 - 17:15