cve/2023/CVE-2023-45316.md
2024-05-25 21:48:12 +02:00

766 B

CVE-2023-45316

Description

Mattermost fails to validate if a relative path is passed in /plugins/playbooks/api/v0/telemetry/run/<telem_run_id> as a telemetry run ID, allowing an attacker to use a path traversal payload that points to a different endpoint leading to a CSRF attack.

POC

Reference

No PoCs from references.

Github