CVE-2016-11068
https://notcve.org/view.php?id=CVE-2016-11068
An issue was discovered in Mattermost Server before 3.2.0. Attackers could read LDAP fields via injection. Se detectó un problema en Mattermost Server versiones anteriores a 3.2.0. Los atacantes podían leer los campos LDAP mediante inyección • https://mattermost.com/security-updates • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') •
CVE-2016-11067
https://notcve.org/view.php?id=CVE-2016-11067
An issue was discovered in Mattermost Server before 3.2.0. It allowed crafted posts that could cause a web browser to hang. Se detectó un problema en Mattermost Server versiones anteriores a 3.2.0. Permitió publicaciones diseñadas que podrían hacer que un navegador web se bloquee • https://mattermost.com/security-updates • CWE-20: Improper Input Validation •
CVE-2016-11066
https://notcve.org/view.php?id=CVE-2016-11066
An issue was discovered in Mattermost Server before 3.2.0. The initial_load API disclosed unnecessary personal information. Se detectó un problema en Mattermost Server versiones anteriores a 3.2.0. La API initial_load reveló información personal innecesaria • https://mattermost.com/security-updates • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2016-11065
https://notcve.org/view.php?id=CVE-2016-11065
An issue was discovered in Mattermost Server before 3.3.0. An attacker could use the WebSocket feature to send pop-up messages to users or change a post's appearance. Se detectó un problema en Mattermost Server versiones anteriores a 3.3.0. Un atacante podría usar la funcionalidad WebSocket para enviar mensajes emergentes a los usuarios o cambiar la apariencia de una publicación • https://mattermost.com/security-updates • CWE-732: Incorrect Permission Assignment for Critical Resource •
CVE-2016-11063
https://notcve.org/view.php?id=CVE-2016-11063
An issue was discovered in Mattermost Server before 3.5.1. XSS can occur via file preview. Se detectó un problema en Mattermost Server versiones anteriores a 3.5.1. Un ataque de tipo XSS puede presentarse por medio de la vista previa del archivo • https://mattermost.com/security-updates • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •