An issue was discovered in Mattermost Server before 3.5.1. XSS can occur via file preview.
CVSS Metrics