cve/2023/CVE-2023-35075.md
2024-05-25 21:48:12 +02:00

839 B

CVE-2023-35075

Description

Mattermost fails to use  innerText / textContent when setting the channel name in the webapp during autocomplete, allowing an attacker to inject HTML to a victim's page by create a channel name that is valid HTML. No XSS is possible though. 

POC

Reference

No PoCs from references.

Github