Mattermost fails to check the "invite_guest" permission when inviting guests of other teams to a team, allowing a member with permissions to add other members but not to add guests to add a guest to a team as long as the guest was already a guest in another team of the server
2024-02-29T09:15:06.563
2025-05-12T13:35:39.400
Analyzed
CVSSv3.1: 4.3 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mattermost | mattermost_server | < 8.1.9 | Yes |
Application | mattermost | mattermost_server | < 9.2.5 | Yes |
Application | mattermost | mattermost_server | < 9.3.1 | Yes |
Application | mattermost | mattermost_server | < 9.4.2 | Yes |