Mattermost Server
cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*, +1 more
- >= 10.5, <= 10.5.9
A vulnerability exists in Mattermost Server versions 10.5.x prior to 10.5.9 that use the Agents plugin. The issue arises because the server fails to properly reject empty request bodies. This flaw enables users to manipulate others into clicking on harmful links through post actions.
Exploitation of this vulnerability could lead to unwanted actions being performed on behalf of the user, potentially including the execution of malicious links.
Users can upgrade to Mattermost Server version 10.11.010.5.10 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.