CVE-2023-1774
31.03.2023, 12:15
When processing an email invite to a private channel on a team, Mattermost fails to validate the inviter's permission to that channel, allowing an attacker to invite themselves to a private channel.Enginsight
Vendor | Product | Version |
---|---|---|
mattermost | mattermost_server | 𝑥 < 7.1.6 |
mattermost | mattermost_server | 7.7.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration