Mattermost fails to properly validate permissions when demoting and deactivating a user allowing for a system/user manager to demote / deactivate another manager
2023-09-29T10:15:10.757
2024-11-21T08:41:16.597
Modified
CVSSv3.1: 2.7 (LOW)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mattermost | mattermost | < 7.8.10 | Yes |
Application | mattermost | mattermost | < 8.1.1 | Yes |