Vulnerability Description
Mattermost 6.3.0 and earlier fails to properly sanitize the HTML content in the email invitation sent to guest users, which allows registered users with special permissions to invite guest users to inject unescaped HTML content in the email invitations.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mattermost | Mattermost | < 6.4.0 |
Related Weaknesses (CWE)
References
- https://hackerone.com/reports/1443567ExploitThird Party Advisory
- https://mattermost.com/security-updates/Release NotesVendor Advisory
- https://hackerone.com/reports/1443567ExploitThird Party Advisory
- https://mattermost.com/security-updates/Release NotesVendor Advisory
FAQ
What is CVE-2022-1002?
CVE-2022-1002 is a vulnerability with a CVSS score of 2.0 (LOW). Mattermost 6.3.0 and earlier fails to properly sanitize the HTML content in the email invitation sent to guest users, which allows registered users with special permissions to invite guest users to in...
How severe is CVE-2022-1002?
CVE-2022-1002 has been rated LOW with a CVSS base score of 2.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-1002?
Check the references section above for vendor advisories and patch information. Affected products include: Mattermost Mattermost.