← back
CVE-2023-49607mediumCWE-754

Playbook plugin crash via missing interface type assertion

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 4.3epss 0.6%
exploitation probability
0.6%top 50% of all CVEs
observed exploitation
nono source reports it
Mattermost fails to validate the type of the "reminder" body request parameter allowing an attacker to crash the Playbook Plugin when updating the status dialog.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Affected products
Mattermost · Mattermost