Mattermost versions 9.6.0, 9.5.x before 9.5.3, and 8.1.x before 8.1.12 fail to fully validate role changes, which allows an attacker authenticated as a team admin to promote guests to team admins via crafted HTTP requests.
2024-04-26T09:15:12.897
2025-05-12T13:43:36.643
Analyzed
CVSSv3.1: 2.7 (LOW)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mattermost | mattermost_server | < 8.1.12 | Yes |
Application | mattermost | mattermost_server | < 9.5.3 | Yes |