Mattermost fails to properly validate the requesting user permissions when updating a system admin, allowing a user manager to update a system admin's details such as email, first name and last name.
2023-08-11T07:15:09.963
2024-11-21T08:34:24.487
Modified
CVSSv3.1: 6.7 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mattermost | mattermost | < 7.8.8 | Yes |
Application | mattermost | mattermost | < 7.9.6 | Yes |
Application | mattermost | mattermost | < 7.10.4 | Yes |