Launchpad.net

CVE 2016-11070

An issue was discovered in Mattermost Server before 3.1.0. It allows XSS via theme color-code values.

See the CVE page on Mitre.org for more details.

References