Post Props Validation Flaw in Mattermost Mobile Apps
CVE-2025-20036
6.5MEDIUM
Summary
Mattermost Mobile Apps prior to version 2.22.0 are susceptible to an improper input validation vulnerability concerning post properties. An authenticated malicious user can exploit this flaw by crafting a malicious post, which can result in a crash of the mobile application. This issue highlights the importance of validating user inputs to maintain application stability and security.
Affected Version(s)
Mattermost 0 <= 2.22.0
Mattermost 2.23.0
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
c0rydoras (c0rydoras)