CVE-2023-4478
Parameter tampering in the registration resulting in blocked accounts to be created
Severity Score
8.2
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
Track
*SSVC
Descriptions
Mattermost fails to restrict which parameters' values it takes from the request during signup allowing an attacker to register users as inactive, thus blocking them from later accessing Mattermost without the system admin activating their accounts.
Mattermost no restringe los valores de los parámetros que toma de la solicitud durante el registro, lo que permite a un atacante registrar a los usuarios como inactivos, bloqueándoles así el acceso posterior a Mattermost sin que el administrador del sistema active sus cuentas.
*Credits:
0AQD (0aqd)
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Track
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2023-08-22 CVE Reserved
- 2023-08-25 CVE Published
- 2024-08-31 EPSS Updated
- 2024-09-30 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://mattermost.com/security-updates | 2023-08-31 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mattermost Search vendor "Mattermost" | Mattermost Server Search vendor "Mattermost" for product "Mattermost Server" | < 7.8.9 Search vendor "Mattermost" for product "Mattermost Server" and version " < 7.8.9" | - |
Affected
| ||||||
Mattermost Search vendor "Mattermost" | Mattermost Server Search vendor "Mattermost" for product "Mattermost Server" | >= 7.9.0 < 7.10.5 Search vendor "Mattermost" for product "Mattermost Server" and version " >= 7.9.0 < 7.10.5" | - |
Affected
| ||||||
Mattermost Search vendor "Mattermost" | Mattermost Server Search vendor "Mattermost" for product "Mattermost Server" | 8.0.0 Search vendor "Mattermost" for product "Mattermost Server" and version "8.0.0" | - |
Affected
|