Mattermost allows an attacker to request a preview of an existing message when creating a new message via the createPost API call, disclosing the contents of the linked message.
{ "cpes": [ "cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*", "cpe:2.3:a:mattermost:mattermost_server:7.7.1:*:*:*:*:*:*:*", "cpe:2.3:a:mattermost:mattermost_server:7.8.0:*:*:*:*:*:*:*" ], "severity": "Medium" }