LOW3.7
GHSA-h3gq-j7p9-x3p4
Mattermost Cross-site Scripting vulnerability
Quick fix
GHSA-h3gq-j7p9-x3p4 — github.com/mattermost/mattermost/server/v8: upgrade to the fixed version with the command below.
go get github.com/mattermost/mattermost/server/v8@v8.1.7Details
Mattermost version 8.1.6 and earlier fails to sanitize channel mention data in posts, which allows an attacker to inject markup in the web client.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/mattermost/mattermost/server/v8
Introduced in:
0Fixed in: 8.1.7Fix
go get github.com/mattermost/mattermost/server/v8@v8.1.7