CVE-2024-32945
Mattermost Mobile Apps versions <=2.16.0 fail to protect against abuse of a globally shared MathJax state which allows an attacker to change the contents of a LateX post, by creating another post with specific macro definitions.
Scoring
- Severity
- LOW
- CVSS base score
- 2.6
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N
- EPSS probability
- 0.24%
- CWE
- CWE-909
- Published
- 2024-07-15
- Last modified
- 2026-03-13
Affected products
- Mattermost Mattermost
- Mattermost Mattermost
Weakness type
Related vulnerabilities
- CVE-2026-40687 — In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource,...
- CVE-2025-8117 — Account Takeover via Reset Password Functionality in PAD CMS
- CVE-2025-54410 — Moby's Firewalld reload removes bridge network isolation
- CVE-2025-54388 — Moby's Firewalld reload makes published container ports accessible from remote hosts
- CVE-2024-53845 — AES/CBC Constant IV Vulnerability in ESPTouch v2
- CVE-2024-8178 — Multiple issues in ctl(4) CAM Target Layer
- CVE-2022-0175 — A flaw was found in the VirGL virtual OpenGL renderer (virglrenderer). The virgl did not properly...
- CVE-2022-0382 — An information leak flaw was found due to uninitialized memory in the Linux kernel's TIPC protocol...