CVE-2016-11071

MEDIUM6.1EPSS 0.36%

Mattermost Server is vulnerable to XSS through lack of link relationship attributes `noreferrer` and `noopener`

Published: 5/24/2022Modified: 11/5/2025
Also known as:GHSA-h3qg-w9j5-wh3mGO-2025-4058

Description

An issue was discovered in Mattermost Server before 3.1.0. It allows XSS because the noreferrer and noopener protection mechanisms were not in place.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM6.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

References (4)