← All credits
Doyensec
33 vulnerability records and advisories credit this contributor.
CVE-2024-39772
Silent Desktop Screenshot Capture
CVE-2024-36250
MFA Code Replay
CVE-2023-7114
Mattermost version 2.10.0 and earlier fails to sanitize deeplink paths, which allows an attacker to perform CSRF attacks against the server.
CVE-2023-6459
Public endpoint /metrics of Calls plugin reveals channel IDs
CVE-2023-6458
Client side path traversal due to lack of route parameters validation
CVE-2023-6202
Insecure Direct Object Reference in /plugins/focalboard/ api/v2/users of Mattermost Boards
CVE-2023-5967
Denial of Service via crashing the Calls Plugin
CVE-2023-5920
Lack Of Secure Keyboard Entry Protection in MacOS Desktop
CVE-2023-5876
Regex DoS from a malicious server enrolled in Desktop
CVE-2023-5875
Lack of Hardening against media exploitation from a remote origin