Mattermost fails to check the "Show Full Name" setting when rendering the result for the /plugins/focalboard/api/v2/users API call, allowing an attacker to learn the full name of a board owner.
2023-03-22T11:15:10.493
2024-11-21T07:39:26.780
Modified
CVSSv3.1: 3.5 (LOW)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mattermost | mattermost | < 7.5.0 | Yes |