CVE-2023-47168: Mattermost
Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.
Mattermost fails to properly check a redirect URL parameter allowing for an open redirect was possible when the user clicked "Back to Mattermost" after providing a invalid custom url scheme in /oauth/{service}/mobile_login?redirect_to=
Affected products
- Mattermost Mattermost: up to and including 7.8.12; from 8.0.0, up to and including 8.1.3; from 9.0.0, up to and including 9.0.1; version 9.1.0 only
Published 2023-11-27. Last modified 2026-06-17.