CVE-2023-5968
4.9
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Exploitability: 1.2 / Impact: 3.6
Source: NVD
Description
Mattermost fails to properly sanitize the user object when updating the username, resulting in the password hash being included in the response body.
Affected (4)
Products: Mattermost: Mattermost
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 7.8.11 |
Related CWEs
CWE-116
Improper Encoding or Escaping of Output
The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
References (2)
Timeline
No history available yet.