Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2, when Single Sign-On OAuth2 is used. An attacker could claim somebody else's account.
Published Jun 19, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows crafted posts that potentially cause a web browser to hang.
Published Jun 19, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS could occur via a goto_location response to a slash command.
Published Jun 19, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. XSS can occur via a link on an error page.
Published Jun 19, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. The X.509 certificate validation can be skipped for a TLS-based e-mail server.
Published Jun 19, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS can occur via OpenGraph data.
Published Jun 19, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to cause a denial of service (channel invisibility) via a misformatted post.
Published Jun 19, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2, when serving as an OAuth 2.0 Service Provider. There is low entropy for authorization data.
Published Jun 19, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. Knowledge of a session ID allows revoking another user's session.
Published Jun 19, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. API endpoint access control does not honor an integration permission restriction.
Published Jun 19, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2, when used as an OAuth 2.0 service provider, Session invalidation was mishandled.
Published Jun 19, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS could occur via the title_link field of a Slack attachment.
Published Jun 19, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 4.1.0, 4.0.4, and 3.10.3. It allows attackers to discover a team invite ID by requesting a JSON document.
Published Jun 19, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage for files is used. A System Admin can achieve directory traversal.
Published Jun 19, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A TOCTOU issue in the chownr package before 1.1.0 for Node.js 10.10 could allow a local attacker to trick it into descending into unintended directories via symlink attacks.
Published Jun 15, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. After a restart of a server, an attacker might suddenly gain API Endpoint access.
Published Jun 19, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. XSS could occur via a channel header.
Published Jun 19, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage for files is used. A System Admin can test for the existence of an arbitrary file.
Published Jun 19, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It discloses the team creator's e-mail address to members.
Published Jun 19, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 3.7.3 and 3.6.5. A System Administrator can place a SAML certificate at an arbitrary pathname.
Published Jun 19, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to gain privileges by using a registered OAuth application with personal access tokens.
Published Jun 19, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. An attacker could create fictive system-message posts via webhooks and slash commands, in the v3 or v4 REST API.
Published Jun 19, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage for files is used. A System Admin can create arbitrary files.
Published Jun 19, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. It allows an attacker to specify a full pathname of a log file.
Published Jun 19, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 4.0.0, 3.10.2, and 3.9.2. CSRF can occur if CORS is enabled.
Published Jun 19, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS attacks could occur against an OAuth 2.0 allow/deny page.
Published Jun 19, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 4.1.0, 4.0.4, and 3.10.3. It allows CSV injection via a compliance report.
Published Jun 19, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. Display names allow XSS.
Published Jun 19, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows SQL injection during the fetching of multiple posts.
Published Jun 19, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. E-mail notifications can have spoofed links.
Published Jun 19, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows attackers to obtain sensitive information (user statuses) via a REST API version 4 endpoint.
Published Jun 19, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 4.5.0, 4.4.5, 4.3.4, and 4.2.2. It allows attackers to cause a denial of service (application crash) via an @ character before a JavaScript field name.
Published Jun 19, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows a bypass of restrictions on use of slash commands.
Published Jun 19, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to gain privileges by accessing unintended API endpoints on a user's behalf.
Published Jun 19, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5, when used as an OAuth 2.0 service provider. Sometimes. resource-owner authorization is bypassed, allowing account takeover.
Published Jun 19, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 4.1.0, 4.0.4, and 3.10.3. It allows attackers to discover team invite IDs via team API endpoints.
Published Jun 19, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 4.4.3 and 4.3.3. Attackers could reconfigure an OAuth app in some cases where Mattermost is an OAuth 2.0 service provider.
Published Jun 19, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows Phishing because an error page can have a link.
Published Jun 19, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An improper authorization check in the User API in TheHive before 2.13.4 and 3.x before 3.3.1 allows users with read-only or read/write access to escalate their privileges to the administrator's privileges. This affects app/controllers/UserCtrl.scala.
Published Jun 2, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In PyYAML before 5.1, the yaml.load() API could execute arbitrary code if used with untrusted data. The load() function has been deprecated in version 5.1 and the 'UnsafeLoader' has been introduced for backward compatibility with the function.
Published Jun 27, 2018 · Updated Aug 5, 2024
High · CVSS 8.4
In NETGEAR ReadyNAS Surveillance before 1.4.3-17 x86 and before 1.1.4-7 ARM, $_GET['uploaddir'] is not escaped and is passed to system() through $tmp_upload_dir, leading to upgrade_handle.php?cmd=writeuploaddir remote command execution.
Published Jun 11, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered on Wireless IP Camera (P2P) WIFICAM cameras. There is Command Injection in the set_ftp.cgi script via shell metacharacters in the pwd variable, as demonstrated by a set_ftp.cgi?svr=192.168.1.1&port=21&user=ftp URI.
Published Jun 11, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The Gentoo app-backup/burp package before 2.1.32 has incorrect group ownership of the /etc/burp directory, which might allow local users to obtain read and write access to arbitrary files by leveraging access to a certain account for a burp-server.conf change.
Published Jun 4, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
nZEDb v0.7.3.3 has XSS in the 404 error page.
Published Jun 5, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The Gentoo app-backup/burp package before 2.1.32 sets the ownership of the PID file directory to the burp account, which might allow local users to kill arbitrary processes by leveraging access to this account for PID file modification before a root script sends a SIGKILL.
Published Jun 4, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The ASUS HiVivo aspplication before 5.6.27 for ASUS Watch has Missing SSL Certificate Validation.
Published Jun 24, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The ASUS Vivobaby application before 1.1.09 for Android has Missing SSL Certificate Validation.
Published Jun 20, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
OPC Foundation Local Discovery Server (LDS) 1.03.370 required a security update to resolve multiple vulnerabilities that allow attackers to trigger a crash by placing invalid data into the configuration file. This vulnerability requires an attacker with access to the file system where the configuration file is stored; however, if the configuration file is altered the LDS will be unavailable until it is repaired.
Published Jun 13, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Huawei HG255s-10 V100R001C163B025SP02 has a path traversal vulnerability due to insufficient validation of the received HTTP requests, a remote attacker may access the local files on the device without authentication.
Published Jun 14, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Huawei smart phones LYO-L21 with software LYO-L21C479B107, LYO-L21C479B107 have a privilege escalation vulnerability. An authenticated, local attacker can crafts malformed packets after tricking a user to install a malicious application and exploit this vulnerability when in the exception handling process. Successful exploitation may cause the attacker to obtain a higher privilege of the smart phones.
Published Jun 14, 2018 · Updated Aug 5, 2024