An issue was discovered in Mattermost Server before 2.2.0. It allows XSS via a crafted link.
CVSS Metrics