When processing an email invite to a private channel on a team, Mattermost fails to validate the inviter's permission to that channel, allowing an attacker to invite themselves to a private channel.
2023-03-31T12:15:06.650
2024-11-21T07:39:52.903
Modified
CVSSv3.1: 4.2 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mattermost | mattermost_server | < 7.1.6 | Yes |
Application | mattermost | mattermost_server | 7.7.1 | Yes |