CVE-2018-21265

Description

An issue was discovered in Mattermost Desktop App before 4.0.0. It mishandled the Same Origin Policy for setPermissionRequestHandler (e.g., video, audio, and notifications).

Risk Information

Base Score
5.3
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS Score
Exploitation Probability
0.195

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2018-21265 are affected in Mattermost Desktop (MSI) (x64) 3.4.0Windows
Vulnerabilities CVE-2018-21265 are affected in Mattermost Desktop (MSI) 3.4.0Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-351481Mattermost (x64) (5.13.1)
PATCH-339198Mattermost (5.8.1)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234