Vulnerabilities
Vulnerable Software
Mattermost fails to sanitize post metadata during audit logging resulting in permalinks contents being logged
CVSS Score
4.5
EPSS Score
0.001
Published
2023-08-11
Mattermost fails to delete the attachments when deleting a message in a thread allowing a simple user to still be able to access and download the attachment of a deleted message
CVSS Score
3.1
EPSS Score
0.003
Published
2023-08-11
Mattermost fails to check if the requesting user is a guest before performing different actions to public playbooks, resulting a guest being able to view, join, edit, export and archive public playbooks.
CVSS Score
6.3
EPSS Score
0.001
Published
2023-08-11
Mattermost fails to properly validate the requesting user permissions when updating a system admin, allowing a user manager to update a system admin's details such as email, first name and last name.
CVSS Score
6.7
EPSS Score
0.0
Published
2023-08-11


Contact Us

Shodan ® - All rights reserved