LOW 3.1 Go
Mattermost Injection vulnerability
GHSA-jcgv-3pfq-j4hr · CVE-2023-35075
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Mattermost fails to use innerText / textContent when setting the channel name in the webapp during autocomplete, allowing an attacker to inject HTML to a victim's page by create a channel name that is valid HTML. No XSS is possible though.
References
Ready to move
Start Securing
Free, no credit card | First findings in minutes